server hacked into

davids355

Super Moderator
Moderator
Executive VIP
Jr. VIP
Joined
Apr 25, 2011
Messages
19,849
Reaction score
28,315
Don't you just love it when you log into your server to be presented with a window open covered in Chinese writing, and in the middle of sniffing IP addresses for port 3389? Bitches.
 
Yea, cleanup time:-) already changed password to something more obscure, looked for any other accounts created or weak accounts.
Exported all security logs so I can check through all successful logins.
Also discovered when they first got in and how - rdp by the looks of it.
And also found their dictionary file- and low and behold, it contained my (now changed) password:-)

Posted via Topify using iPhone/iPad
 
Welp, it's a good thing you know what you needed to do right away. Others are not fortunate enough and all they can do for several minutes, even hours, is panic.
 
Yea, cleanup time:-) already changed password to something more obscure, looked for any other accounts created or weak accounts.
Exported all security logs so I can check through all successful logins.
Also discovered when they first got in and how - rdp by the looks of it.
And also found their dictionary file- and low and behold, it contained my (now changed) password:-)

Posted via Topify using iPhone/iPad

If you feel like sharing the dictionary file let me know, I would like to add it to my collection.
Before anybody asks, no I am using them for nefarious purposes, I have an interest in computer security.

For those worried about their password security, here are some interesting articles:
http://uwnthesis.wordpress.com/2012/08/30/top-10000-passwords-are-used-by-98-8-of-all-users/
http://digitaljournal.com/article/335497
http://xato.net/passwords/more-top-worst-passwords/
http://www.visualizing.org/visualizations/top-1000-passwords
http://dazzlepod.com/disclosure/
http://www.skullsecurity.org/wiki/index.php/Passwords


Edit : The line above should read "Before anybody asks, no I am NOT using them for nefarious purposes, I have an interest in computer security.
 
Last edited:
Is it a cloud based server? If so, I would dump it and start a new instance. You will never fully clean a hacked Windows OS. It's just swiss cheese with its undeletable files, unstoppable services, infinitely complicated registry and you name it....my worst nightmare was to work in a Microsoft server rack years ago.
 
That is the worst, be sure to change all of your passwords and such mate. Sorry to hear
 
Is it a cloud based server? If so, I would dump it and start a new instance. You will never fully clean a hacked Windows OS. It's just swiss cheese with its undeletable files, unstoppable services, infinitely complicated registry and you name it....my worst nightmare was to work in a Microsoft server rack years ago.

Yes it is. But it is also production environment, so hard to take down:(

i will be monitoring everything for a few weeks - auditing logins etc, and looking for any back doors left open.
 
antichrist said:
Maybe this is a sign to learn chinese XD

Lol yea.

Posted via Topify using iPhone/iPad
 
i have already faced the problem .. now am on new server and making my passwords strong .. but still i cant forget those days when i saw those hacked pages
 
Not sure if this is still the case, but up until Windows 7 (maybe on Windows 7 as well...), just naming any .exe 'lsass.exe' meant that it was completely unable to be terminated - regardless of the checksum of the file.

If that doesn't make you want to shoot the Windows developers in the face, I don't know what does...
 
Daaaammmmmnnnnn dude, that sucks :(

Good to see you caught it quick though :D



If that doesn't make you want to shoot the Windows developers in the face, I don't know what does...

lololol
biggrin.png
 
Last edited:
Whoops, I guess I could have just edited my previous post. Mods/Admin you can delete this if you see it.

Sorry about that.
 
Few days ago I`m was hacked by a "terorist" Algerian...I forgot his nickname, but he leaved a photo with 1 terrorist xD
 
Back
Top