Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > Server Hacked Logon Type 2

Reply
Thread Tools Display Modes

Server Hacked Logon Type 2

 
 
jeffhsu
Guest
Posts: n/a

 
      03-13-2011
I have a server running Server 2003 SBS, running IIS 6.
It has been hacked.
The hacker can create its own hidden user account, with admin rights
steal files, etc
I have deleted all users, change password, clean up registry,
tried patching and all sorts of methods to retify the hacked situation.

But the hacker can still login using user account not in system, as
administrator rights, turn on diabled services like telnet, remote, etc

In the event viewer , security

Successful Logon:
User Name: heng$
Domain: NS3
Logon ID: (0x0,0x98EDE8)
Logon Type: 2
Logon Process: Advapi
Authentication Package: Negotiate
Workstation Name: NS3
Logon GUID: -
Caller User Name: NS3$
Caller Domain: WORKGROUP
Caller Logon ID: (0x0,0x3E7)
Caller Process ID: 1500
Transited Services: -
Source Network Address: -
Source Port: -


Can anyone advise what is there that can be done to retify the hacked
situation
Or explain how the user login in the 1st place?



--
+-----[ SERVER SIGNATURE ]--------------------------
| Article posted via Web Developer's USENET Archive
| http://www.1-script.com/forums/
| Web and RSS gateway to your favorite newsgroup -
| microsoft.public.windows.server.security
+---------------------------------------------------

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
I also have an error 646 in Windows update. Please help. Jose Windows Update 12 01-09-2010 01:00 PM
Re: Time Sync Problem on AD 2003 domain Meinolf Weber [MVP-DS] Active Directory 11 12-02-2009 09:30 PM
The local domain controller could not connect with - 2008 boe Active Directory 9 11-22-2009 01:05 AM
Error not able to loging after upgrading domain controller Alexyy Active Directory 6 11-10-2009 06:09 AM
Stop Error 0x0000007b Louis LeBrun Windows Vista Installation 17 07-05-2006 09:00 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59