Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Help with server 2000 and/or possible virus problem/hack attack

Status
Not open for further replies.

S1ID3R

Technical User
Jun 26, 2003
2
GB
ok we had a strange thing happening here yesterday, we are running a few servers, with windows 2000 server, all patched and with the appropriate updates, however, yesterday we were made aware that:

"complaints that we are receiving related to apparent CodeRed type TCP port 80 activity (which could of course be web server break in attempts under the control of a human user, rather than virus or worm related activity)."

however a full virus scan of the machince revealed nothing, the other option was:

"TCP port 4889 may be used by the ICQ protocol, so the TCP port 4889 scans could be the result of someone attempting to "spamvertise" using ICQ mass messaging techniques."


if ANYONE has any idea how to stop this happening, or what exactly it is, please let me know as soon as possible.Cant seem to find anything obviously wrong with the machine. Thanks a lot.
 
Who is it that "made you aware" of this?

Generally, if someone "made you aware" of this problem, it's somebody that is watching the firewall logs or something of the sort.

If this is so, are the attacks coming from WAN to LAN? (Internet to your internal network)? if not, how is it you can see these attacks?

Determining the source will be the answer to your problem.






"In space, nobody can hear you click..."
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top