Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Hacked / Cracked

Status
Not open for further replies.

Ovatvvon

Programmer
Feb 1, 2001
1,514
US
Hi all,
I have win2k advanced server with IIS 5.
I recently (within the last 24 hours) had someone hack into my system. They did somthing so that whenever any one of my sites post information to the server via a form, or whatever, it stops the site, and displays a page that they designed, with the same url that was originally the target. I've gone all through the code, but it's not there, and makes sense to me that it's not since it's all my sites, whenever users log in (via database authentication).

Does anyone know how this could be done? My guess is they altered IIS files somehow, but if anyone knows what exactly may have happened, or how to cure it without totally reloading, I'd really appreciate it!!
-Ovatvvon :-Q
 
Also, if you have any idea's of how they went about getting in, I'd appreciate that too so I can perhaps prevent this from happening again.
Thanks!!
-Ovatvvon :-Q
 
Some advices:
a) Pull the Internet cable off, connect to your site, see what happens, if the same page is showned, then the page is on your hard drive. You should look for it on your hard drive, with Find File putting some key words from the file.
b) After you have found it, do not delete it, just renameit or move it to see where the reference come from.
c) You can also try to enable for a short period the basic Authentication from the IIS Management Console to see what happens.
d) Look for the log files of you IIS, look inside maybe you will find something to give you an ideea of the agressor.

Reinstall IIS as a final measure.
To avoid this in future, buy your self a firewall program and read more from the microsoft site about the weknesses of IIS.

Hope this helps,
{By the way, I like Marines, I made the army as a Mountain Hunter and I like the tough life :))}


s-)

Blessed is he who in the name of justice and good will, shepards the week through the valley of darknees...
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top