Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations TouchToneTommy on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

NT4 Admin Attack

Status
Not open for further replies.

ken2000

IS-IT--Management
Jun 19, 2003
1
US
Does anyone know of a good program that can track an IP address of someone attempting to hack a administrator or admin username on our network? We have repeated logs on a webserver that show attempt after attempt but the NT log just shows a bogus domain and workstation name and no other useful information. We believe the attempt is coming from outside the network. We have also attempted to match the times of the attempts to all .log files and cannot seem to find a match. Anyone have any ideas? Thanks in advance, Ken Grimes
 
I can't think of something at the moment but, you may want to rename you admin and/or administrator accounts. These names are default and the majority of networks I'm sure still have them... makes hacking a little easier
 
Why are you running a webserver without a firewall? Get one, and only allow port 80 to the webserver. That will stop the attacks. Firewalls are cheap if not free.

Once that's done you can track attacks using the firewall logs.

Change your admin password. Better yet, rename the admin account, and change the password.

You can always run a sniffer, or an ids to see the attack traffic.
- sniffer
- IDS


I'll see your DMCA and raise you a First Amendment.
 
Please make sure you have disabled File and Print Sharing on the network cards that are exposed to the Internet, and like the previous recommendation said, get a firewall package and only open the ports required for your site.

-Tony
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top