Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc.

Go Back   Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc. > >>Network Information & News and Announcements > Network / Server Status
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Network / Server Status Please check often for network / Server updates here!

Reply
 
Thread Tools Display Modes
  #16  
Old 08-17-2005, 05:04 PM
Jim Nayzium Jim Nayzium is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
I clicked on the ID numbers and saw nothing with NT at the beginning...where would I go exactly. Forgive the idiotness...I am very green.
Reply With Quote
  #17  
Old 08-17-2005, 05:06 PM
dpyers's Avatar
dpyers dpyers is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Quote:
Originally Posted by drobee
What's the easiest way to determine which users are on NT33?
If you know their domains, entering a ficticions subdomain (http://XX.example.com) in a bowser will return the server for domains hosted on NT.
__________________
Reply With Quote
  #18  
Old 08-17-2005, 05:10 PM
Jim Nayzium Jim Nayzium is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
ok,

I entered XX@blueeyedpanda.com and it went straight to my normal blueeyedpanda.com??

sorry again. will try a different browsewr
Reply With Quote
  #19  
Old 08-17-2005, 05:12 PM
dpyers's Avatar
dpyers dpyers is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
edited my post to change the @ to a .
sorry
__________________
Reply With Quote
  #20  
Old 08-17-2005, 05:12 PM
Jim Nayzium Jim Nayzium is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
OK, wow, the email message used an @ sign instead of a . syntax...i am a moron
Reply With Quote
  #21  
Old 08-17-2005, 05:13 PM
Brangwyn Brangwyn is offline
T3CHN0 STUD
Vortech Inc. Customer
 
Location: New Zealand (Wellington)
I highly recommend that you all set up HSphere to send you a copy of all signup emails, you can then store them in a folder and very easily search these emails to get a list of customers on any one server (the standard signup emails has the server name/alias they're assigned as the FTP URL). Doing this I found all my effected customers in just a few seconds.
Reply With Quote
  #22  
Old 08-17-2005, 05:14 PM
Jim Nayzium Jim Nayzium is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
thanks for the help.

All said either NT4 or NT17, so I have no worries correct?
Reply With Quote
  #23  
Old 08-17-2005, 05:17 PM
devorem's Avatar
devorem devorem is offline
"right to lifer"
Vortech Inc. Customer
 
Location: Cow Country, USA
right
Reply With Quote
  #24  
Old 08-17-2005, 05:18 PM
Jim Nayzium Jim Nayzium is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
I do have it send them emails...good idea
Reply With Quote
  #25  
Old 08-17-2005, 05:48 PM
admin's Avatar
admin admin is offline
Vortech Inc. Owner
Owner
 
Location: Orlando FL
Send a message via ICQ to admin
Quote:
Originally Posted by devorem
I couldn't tell you for sure if it was related or not, but one of my clients (on NT33) had their index.htm file replaced over the weekend with one that featured some gruesome pictures of mutilated children and it said:

YOU ARE CAUSE OF ALL THAT HAPPENED

FOR IRAQ,

FOR AFGHANISTAN,

FOR PALESTINE,

FOR ALL COUNTRIES UNDER SIEGE LIKE ABOVE.

TO BE CONTINUED...

HACKED BY Cool_Baby & sanaleskiya

TURKISH HACKERS

I was able to replace the file with a copy from Google cache. Apparently, my client didn't catch it in time and the hacked copy had already been backed up so Vortech wasn't able to restore it. I bought a copy of "Site Shelter" to back up my client's sites as a result of all of this.


I don't think this came from the same group or attackers. They started there little mess around 1:30pm yesterday. But I would for sure change there password.
__________________
Brad Pugh
http://www.vortechhosting.com
------

Local System/Network Monitor
http://nagios.hsphere.cc/
Login:guest Pass:guest
XML FEED http://nagios.hsphere.cc/feed.xml
------

My Other Life:
Reply With Quote
  #26  
Old 08-17-2005, 06:51 PM
Brangwyn Brangwyn is offline
T3CHN0 STUD
Vortech Inc. Customer
 
Location: New Zealand (Wellington)
You say attack, but you sure this wasn't just the two variant worms that got into the wild yesterday? ... from the little you've said about it, it sounds like it may have been,
Reply With Quote
  #27  
Old 08-17-2005, 11:27 PM
craigdunlop's Avatar
craigdunlop craigdunlop is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
What data would have been exposed to these hackers? Is it just the data/databases of these accounts on NT33 or is it also their account information that HSPhere stores, such as user details, passwords, etc? Does this mean it stores these on each local machine unencrypted? If I use a ssl cp, would that have helped to prevent their account details being pilfered?
Reply With Quote
  #28  
Old 08-18-2005, 04:39 AM
byron's Avatar
byron byron is offline
BANNED
Banned
 
Location: Winter Park, FL
These were not the recent worms, because the worms affect RPC and cause unattended shutdowns and other less-critical annoyances. This was more of a backdoor/Trojan type of exploit that offered the hacker remote access, which they used to install other agents that basically "sniffed" out information over a 24-48 hour period before it was discovered and removed. We patched this vulnerable hole and haven't seen the similar vulnerabilities on any other box. The virus scans are something I've wanted to have in place for a while now, and firewalling is an even better manuever.
Reply With Quote
  #29  
Old 08-18-2005, 09:38 AM
Brangwyn Brangwyn is offline
T3CHN0 STUD
Vortech Inc. Customer
 
Location: New Zealand (Wellington)
Pretty sure at least one of the worms that surfaced last 48 hours opened up a backdoor of some sort, spent a good portion of yesterday disinfecting a corporate network of the pesky little buggers.

Virus scanning, realtime file sanning? that will add a reasonable overhead won't it? think every time a website logfile is updated, email placed in the SMTP Q etc. I've always led to believe that file scanning on a webserver really wasn't worth the overhead and not to mention the aggressive file locking problems some of them can cause.

Not a big fan of "extreme" firewalling myself, they do help with some things, but at the end of the day, securing the server is the best first line of defence, never have a service open on a port that you don't want someone to gain access too etc along with proactive monitoring of listening ports, lets face it your never going to stop IIS exploits with a firewall unless you go to some extreme measures. Just so I don't come across sounding all negative, on the flipside firewalls can be a great defence for denial of service attacks, making sure traffic doesn't "leak" from your server etc especially if used with a good network architecture that includes seperation of sensitive segments using vlans etc.
Reply With Quote
  #30  
Old 08-18-2005, 10:32 AM
admin's Avatar
admin admin is offline
Vortech Inc. Owner
Owner
 
Location: Orlando FL
Send a message via ICQ to admin
No we can't do realtime, your right it would kill the servers.

The firewall is/was ( having issues with getting ftp to work even with the 1024+ ports open ) going to be just to block ports *not* used by use below 1024 and open 1024 and up. We would then use snort to look for anything that is now DNS, SMTP or FTP in these high ports. Since nothing but those things should really be running up there besides a few other things we already now about.

Firewall and snort are a little to reactive for me. Like you I like to be more active in makeing sure the box is 100% secure. But if we put all 4 things together it should make things a bit better all around. That is if we can get the firewall setting to let ftp work.
__________________
Brad Pugh
http://www.vortechhosting.com
------

Local System/Network Monitor
http://nagios.hsphere.cc/
Login:guest Pass:guest
XML FEED http://nagios.hsphere.cc/feed.xml
------

My Other Life:
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
NT33.hsphere.cc byron Network / Server Status 2 07-23-2005 02:35 AM
phpBB Continues To Be a Hack Vector admin Chit Chat Public 5 05-09-2005 03:08 PM


All times are GMT -5. The time now is 10:56 PM.


Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Vortech Inc. ©2005
Page generated in 0.76680 seconds with 19 queries
[Output: 109.83 Kb. compressed to 100.94 Kb. by saving 8.89 Kb. (8.10%)]