Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > Re: Thngs to check for in a hacked DC?

Reply
Thread Tools Display Modes

Re: Thngs to check for in a hacked DC?

 
 
Meinolf Weber [MVP-DS]
Guest
Posts: n/a

 
      09-04-2009
Hello John,

Unfortunal you can not see it that easy, you have to use the advanced view
in security tab of OUs for example to check for delegated control. Also this
may help:
http://gallery.technet.microsoft.com...9-d4b0dc408091

Additional check this page for scripting solutions:
http://gallery.technet.microsoft.com...5D.Value=dacls

Rebuilding will only help if you can go back to a state/date where the system
wasn't hacked. So do you have that old backups with at least a healthy system
state?

Otherwise you can only start from scratch in my opinion. If you just add
a new installed DC to the domain this will not prevent from copying the maybe
granted permissions from AD to the new DC also.

A limited option can be to use LDIFDE to export from the old to the, if decided
to do it, new domain:
http://support.microsoft.com/kb/237677

This will not have the full option of AD database but parts of it can be
rebuild na dyou can control the texfile also before importing.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> I won't go into the reasons here but I think
> our domain controllers has been hacked. We have
> a small domain of about 50 people. My question
> is what things should we do to cleanup. We plan
> to rebuild the domain controllers. We will also
> change everyone's password and check group
> policy and all the groups we have setup,
> especially the Admin group. I want to check
> to see if any user account has been delegated
> any privileges but I don't see a way to view
> this. Is there a way to view delegated privileges?
> We also will run the baseline security analyzer
> on the computers. Of course we will run
> anti-virus/anti-spyware on the computers. Are
> there other things we need to check for? Thank you.
> John
>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Microsoft Vulnerability Check on Trend Micro Housecall Virus Check Eugene London Windows Update 1 10-21-2005 11:48 PM
Microsoft Vulnerability Check on Trend Micro Hosuecall Virus Check Eugene London Windows Update 0 10-14-2005 03:23 PM
Microsoft Vulnerability Check on Trend Micro Hosuecall Virus Check Eugene London Windows Update 5 10-12-2005 05:30 PM
Has my DC been hacked? Adam Atkinson Server Security 6 03-25-2005 05:30 AM
Re: Getting Hacked Kevin Gal Windows Small Business Server 5 04-28-2004 09:50 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59