I think I'm being hacked

10Mhz8086

Distinguished
Jan 31, 2002
107
0
18,680
Strange things are happeneing to my little server....

I run a small Win2k SRV machine on my 768/128k DSL line and it also acts as a gateway running NAT routing for my local network. For a firewall I run BlackICE defender and the only service thats turned on is HTTP, all the other netservices have been turned off.

The strange things that have been happening to it is that one day I logged in and some how FTP was turned on. I usually check the HTTP logs daily and when I noticed that a FTP log was created I freaked out. According to the log, several people tried to login and create a file/folder, but were denied access.

Then I sometimes download stuff from WinMX only to find my computer in some chat room or in another screen than what I had left it at. Sometimes my download bandwidth gets cut in half and my upload speed is also mysteriously cut in half, like if someone was connected to it from the internet. I can reboot the machine and it gets backup to speed...

I have the latest version Win2k SRV SP2 with all the IIS patches and I have installed secruity rollup package. I run Macfee netshield sp1 with the latest DAT files and no viruss are found on my system.

The only ports open are 80,20/21 and 6699 for WinMX. All the rest have been blocked by Blackice. And I have disabled NetBIOS on the adaptor thats connected to my DSL modem.

I have terminal sevices enabled so I can administer my machine with out a monitor from inside the lan, but I made sure it only listens to reqests from inside the lan.

All my passwords are pretty complicated so I doubt anyone could guess them...

Anyone???
 

10Mhz8086

Distinguished
Jan 31, 2002
107
0
18,680
I have a total 4 computers

1 - My P42G@2.2\WINXP <-- mainly used for games and surfing
2 - Her PIII800\WINXP <-- chat and butterflies
3 - A IBM 600E laptop\.NET SRV <-- PDC/PRN server
4 - The PII400/WIN2K SRV <-- HTTP/NAT/GATEWAY server
 

Lucol

Distinguished
Dec 31, 2007
177
0
18,680
You should try shutting down the WinMX port, and see if it keeps happening. You never know, there might be a WinMX exploit.
 

PoolSnoopy

Distinguished
Dec 14, 2001
22
0
18,510
You should close ports 20 and 21. They are for FTP. So no wonder that you had log entries for these ports.
PoolSnoopy

cigarettes taste much better since I'm looking for a cure for cancer :tongue:
 

10Mhz8086

Distinguished
Jan 31, 2002
107
0
18,680
I think It has to do with WinMX, maybe there is some backdoor or backdoor virus (that hasn't been discovered by mcafee) in it.

Just yesterday I had left WinMX on for a little bit and all of a sudden Mcafee and HTTP was mysteriously turned off. I rebooted the machine, checked to make sure I had the latest dat files, ran a virusscan and everything was ok.

This is really annoying me and pissing me off!

I leave port 20/21 open in Black ICE because once in a while I have to remotely download stuff from my PC. But I normally leave the service turned off and when it is turned off and people try to access FTP, it doesn't create a log file. It will only create a log file if the service is turned on.

The FAA issued a wind sheer warning for my computer case, I think I have one to many fans in it...
 

Yahiko81

Illustrious
Jul 17, 2001
10,987
0
40,780
I'd get rid of Black Ice and put on Zone Alarm. Seagate also makes a good Utility that blocks network traffic. You can disable inbound FTP and enable Outbound FTP. I'd really suggest getting a different firewall. Also try going to <A HREF="http://www.grc.com" target="_new">here</A> and testing out your firewall and such.

<b><font color=green>Lizards</b></font color=green> for <b>THGC</b> Mascot!!!
 

10Mhz8086

Distinguished
Jan 31, 2002
107
0
18,680
Great, looks like really BlackIce sux! :(

Time to try Zone alarm? But I already paid my $40 for Blackice :(

<i>"The FAA issued a wind sheer warning for my PC, I think I may have one to many fans in it..."</i>
 

DanielR

Distinguished
Sep 18, 2001
74
0
18,630
i would guess that if they know and eveyone else knows that they have a huge issue, i would think they will fix it. and they should give you the lastest, fixed version for free... I would call and bitch at them make them tell you that it was a probelm with their software and they will either refund the cost or give a free porduct. With such empahsis on internet security, the liability of that software is huge! Make them understand how important your computers are, you could even sue if you lost money or something.

just a thought. I'd be steaming if i found out that the software that i paid for doesn;t do what it says it can do.

who ever has the most ram when they die wins!
 

CALV

Distinguished
May 17, 2001
1,731
0
19,780
just a thought. I'd be steaming if i found out that the software that i paid for doesn;t do what it says it can do.
Thats why they have an EULA- you know the one, the bit where you just click ACCEPT without reading it :(


If they squeeze olives to get olive oil, how do they get baby oil?
 

TRENDING THREADS