•   Notifications
  • Welcome to our forums

    Join us now to get access to all our awesome features. Once registered and logged in, you will be able to create topics, post replies, give reputation to your fellow members, get your own private messenger, and so, so much more.

    + Reply to Thread + Post New Thread
    Results 1 to 4 of 4

    Thread: My Win2k server web site was hacked last nite, please help !
  • Share This Thread!
    • Share on Facebook
    1. #1

      My Win2k server web site was hacked last nite, please help !

      I am currently running my personal web site on my win2 advanced server with SP3 plus all the up-to-date Security patches but it was hacked last nite by a hacker. I am using my "E" drive to store all my web html files under the folder called "wwwroot", in order to increase maxium security of my web site being hacked, I have 2 quick questiosn for you guys:

      Currently, for the permissions of My "wwwroor" folder on my E Drive like the following, may I know what should be the best combination ?

      a. Myself (with full control)

      b. Everyone (Read & Execute, Listfolder contents and Read)


      In addition, do I have to ONLY add the following persmissions for security for my whole "E" drive ?

      a. Myself (with full control)

      b. Everyone (Read & Execute, Listfolder contents and Read)


      Please advise ASAP.

    2. #2

      Re: My Win2k server web site was hacked last nite, please help !

      Originally posted by 456
      I am currently running my personal web site on my win2 advanced server with SP3 plus all the up-to-date Security patches but it was hacked last nite by a hacker. I am using my "E" drive to store all my web html files under the folder called "wwwroot", in order to increase maxium security of my web site being hacked, I have 2 quick questiosn for you guys:

      Currently, for the permissions of My "wwwroor" folder on my E Drive like the following, may I know what should be the best combination ?

      a. Myself (with full control)

      b. Everyone (Read & Execute, Listfolder contents and Read)

      ************* BAD idea to allow Listfolder contents.
      *************Can be exploited. If you need to give view
      *************of files, use ASP or hard code in HTML.

      In addition, do I have to ONLY add the following persmissions for security for my whole "E" drive ?

      a. Myself (with full control)

      b. Everyone (Read & Execute, Listfolder contents and Read)

      *************NTFS Permissions should not need to be
      *************messed with; use IIS to control access!

      Please advise ASAP.

    3. #3
      Join Date
      Feb 2002
      Location
      The guardhouse at Bangla's mansion!
      Posts
      170
      make sure you have the read/execute permissions done right. also check M$ - there are a few new post-SP3 fixes -- not all may apply to your 2K version requirements.
      Last edited by kugmo; 30-11-2002 at 23:24.

    4. #4
      Join Date
      Nov 2001
      Location
      Hong Kong
      Posts
      763
      just out of interest what was the damage done ?
      well - for group "everyone" they only need read access.
      - - -
      though u should use a web server app with better user access control -
      try the demo/trial version of VisNetic WebSite
      http://www.deerfield.com/products/vi...site/security/


    Posting Permissions

    • You may not post new threads
    • You may not post replies
    • You may not post attachments
    • You may not edit your posts
    Powered by vBulletin™ Version 4.0.3 Copyright © 2012 vBulletin Solutions, Inc. All rights