Click here to get back home

Mpack Intrusion

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Mpack Intrusion a 11-06-2007
Posted by a on November 6, 2007, 5:32 am
Please log in for more thread options
Hi,
in the last weeks the company's server web was suffering continues attacks
and intrusions on the part of Mpack.
The consequence is that the pages of the websites dirtied with malignant
IFRAME tags that refer to address housing
Malware.
The SO web server Win2003 standard edition SP2, of course updated with
windowsupdate that is running SQL Server ent edition SP4.
The Symantec antivirus is always updated and has never reported anything.
Is there a procedure to be applied to the server, any tools that can remove
the possibility of intrusions?

thanx to all

sorry for poor English



Posted by S. Pidgorny on November 7, 2007, 4:04 am
Please log in for more thread options
This can be done by accessing the server using valid access and credentials.
If you cannot afford rebuilding from scratch, I'd start with making content
read-only and applying strict auditing together with alerting to fing out
which user account is changing the content.

Using other malware scanners and ro9otkit revealers can also help.

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

* http://sl.mvps.org * http://msmvps.com/blogs/sp *

> Hi,
> in the last weeks the company's server web was suffering continues attacks
> and intrusions on the part of Mpack.
> The consequence is that the pages of the websites dirtied with malignant
> IFRAME tags that refer to address housing
> Malware.
> The SO web server Win2003 standard edition SP2, of course updated with
> windowsupdate that is running SQL Server ent edition SP4.
> The Symantec antivirus is always updated and has never reported anything.
> Is there a procedure to be applied to the server, any tools that can
> remove the possibility of intrusions?
>
> thanx to all
>
> sorry for poor English
>



Similar ThreadsPosted
Problems with backing up security database. Intrusion? February 10, 2006, 12:56 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap