![]() |
|
|||||||
| Network / Server Status Please check often for network / Server updates here! |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
||||
|
||||
|
NT33 Possible Hack Attempt!!
We will be rebooting NT33 due to an attack on the system with in the next 10 to 15 min to fix some issues.
We will be sending out an email to all customers once this has been fully done, we will ask all resellers to notify there customers to change there FTP and SQL passwords at that time to be 100% safe. Please change your password at this time or ASAP if you are NT33. The issue seems to have come from a Microsoft Hole in the OS that has now been fixed and patched after calling Microsoft about this issue. We have also applied this patch to all windows 2000 boxes. We are also making a few changes that should also help prevent this from happening again, e.g. using Patch Quest ( http://www.securecentral.com/products/patchquest/ ) and Anti Virus software on all the systems to help keep you and them a bit safer. We are also looking in to better fire walling the network, the issues there is passive FTP, we are going to talk about this today in our meeting to see if we can't find a work around for this today. This will help a lot if we can find a way to do this today. Thank you and we are very sorry about the issue and are doing everything we can like I said to make our systems 100% safe.
__________________
Brad Pugh http://www.vortechhosting.com ------ Local System/Network Monitor http://nagios.hsphere.cc/ Login:guest Pass:guest XML FEED http://nagios.hsphere.cc/feed.xml ------ My Other Life:
Last edited by admin : 08-17-2005 at 02:56 PM. |
|
#2
|
||||||||||||
|
||||||||||||
|
Quote:
__________________
|
|
#3
|
||||
|
||||
|
No this is more less to scan the boxes to keep them from getting a virus or hack attempt.
It will scan the files in your FTP to be sure there is no virus in there and remove it if there is. But it will not be checking that in real time.
__________________
Brad Pugh http://www.vortechhosting.com ------ Local System/Network Monitor http://nagios.hsphere.cc/ Login:guest Pass:guest XML FEED http://nagios.hsphere.cc/feed.xml ------ My Other Life:
|
|
#4
|
|||||||||||
|
|||||||||||
|
Easiest way to determine which users are on NT33
What's the easiest way to determine which users are on NT33?
|
|
#5
|
||||
|
||||
|
never mind
__________________
David Francis Soky.net, llc http://www.SoKy.net Soky Happenings Magazine http://www.SokyHappenings.com
Last edited by soky : 08-17-2005 at 02:51 PM. |
|
#6
|
||||||||||||
|
||||||||||||
|
was just trying to figure that out myself....got to be an easy way..
__________________
goodbye idevaffiliate, you can kiss my @$* with your poor support and broken script, I am now using post affiliate pro 3 |
|
#7
|
||||
|
||||
|
I was able to find mine quickly enough by...
1) Opening admin account 2) Searching for all accounts 3) Logging on to each account in the list 4) Clicking the file manager in the quick access page 5) Read the address bar and it will show the box (http://nt38.domain.com......) It was quick enough since Vortech keeps their servers so clean and the HSphere control panel is so responsive. (whew) I'm a Windows only reseller so I don't know about Unix garba... eh... stuff. (Laughing... don't kill me.)
__________________
David Francis Soky.net, llc http://www.SoKy.net Soky Happenings Magazine http://www.SokyHappenings.com
|
|
#8
|
||||
|
||||
|
Quote:
Soky there is an easier way to do this. 1) Opening admin account 2) Searching for all accounts 3) Click the account ID number. We have a way on our side to search for users on servers but it just lists all the users. We can't cut it down to just a reseller or I would offer to do that to make it easier. It is safe to now change all passwords and please do this ASAP.
__________________
Brad Pugh http://www.vortechhosting.com ------ Local System/Network Monitor http://nagios.hsphere.cc/ Login:guest Pass:guest XML FEED http://nagios.hsphere.cc/feed.xml ------ My Other Life:
|
|
#9
|
||||
|
||||
|
The new firewall rules are also now in place. If you have any issues please let us know.
We are also updating our rules for snort as well, so we will be watching ports 1024 and up very close for things that should not be there now.
__________________
Brad Pugh http://www.vortechhosting.com ------ Local System/Network Monitor http://nagios.hsphere.cc/ Login:guest Pass:guest XML FEED http://nagios.hsphere.cc/feed.xml ------ My Other Life:
|
|
#10
|
||||
|
||||
|
Quote:
Oh... yeah... that's slick. Thanks.
__________________
David Francis Soky.net, llc http://www.SoKy.net Soky Happenings Magazine http://www.SokyHappenings.com
|
|
#11
|
|||||||||||
|
|||||||||||
|
I am having problems with Using passive FTp on NT39 as well as NT9. Is this the same issue?
|
|
#12
|
|||||||||||
|
|||||||||||
|
True Hack attempt? or just Zotob which started doing the rounds yesterday ?
|
|
#13
|
||||||||||||
|
||||||||||||
|
I couldn't tell you for sure if it was related or not, but one of my clients (on NT33) had their index.htm file replaced over the weekend with one that featured some gruesome pictures of mutilated children and it said:
YOU ARE CAUSE OF ALL THAT HAPPENED
FOR IRAQ, FOR AFGHANISTAN, FOR PALESTINE, FOR ALL COUNTRIES UNDER SIEGE LIKE ABOVE. TO BE CONTINUED... HACKED BY Cool_Baby & sanaleskiya TURKISH HACKERS I was able to replace the file with a copy from Google cache. Apparently, my client didn't catch it in time and the hacked copy had already been backed up so Vortech wasn't able to restore it. I bought a copy of "Site Shelter" to back up my client's sites as a result of all of this. |
|
#14
|
|||||||||||
|
|||||||||||
|
If I am on NS1 - NS4 only, then I have no worries and don't need to change my passwords correct??
NT shows up nowhere on my ID listings.... |
|
#15
|
||||||||||||
|
||||||||||||
|
Those are your name servers/DSN servers. That is not what we're talking about. You need to check to see what web server your sites and the sites of your customers are on.
|
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| NT33.hsphere.cc | byron | Network / Server Status | 2 | 07-23-2005 02:35 AM |
| phpBB Continues To Be a Hack Vector | admin | Chit Chat Public | 5 | 05-09-2005 03:08 PM |