Results 1 to 4 of 4

Thread: My Win2k server web site was hacked last nite, please help !

  1. #1
    Member
    Join Date
    Mar 2002
    Posts
    153

    My Win2k server web site was hacked last nite, please help !

    I am currently running my personal web site on my win2 advanced server with SP3 plus all the up-to-date Security patches but it was hacked last nite by a hacker. I am using my "E" drive to store all my web html files under the folder called "wwwroot", in order to increase maxium security of my web site being hacked, I have 2 quick questiosn for you guys:

    Currently, for the permissions of My "wwwroor" folder on my E Drive like the following, may I know what should be the best combination ?

    a. Myself (with full control)

    b. Everyone (Read & Execute, Listfolder contents and Read)


    In addition, do I have to ONLY add the following persmissions for security for my whole "E" drive ?

    a. Myself (with full control)

    b. Everyone (Read & Execute, Listfolder contents and Read)


    Please advise ASAP.

  2. #2
    Member
    Join Date
    Oct 1999
    Location
    Ottawa, Canada
    Posts
    378
    Unfortunately changing permissions isn't enough to protect your from hacks. It may prevent hackers from defacing your website if the webserver doens' thave write access to the website directory, but there are still alot of underlying problems in IIS/IE/EXPLORER/WINDOWS that you can't fix. I'd recommend putting a firewall in front of the box,or installing firewall software. If it's just a basic webserver then the only open ports from the outside should be port 80. You will also want to use iislockd.exe (from microsoft) to tweak iis to make it more secure.

    good luck.'

    ~Paul
    |}~(O)~{|

  3. #3
    Member
    Join Date
    Mar 2002
    Posts
    153
    Hello acid_burn~187

    Thanks for your suggestion.

  4. #4
    Member bassinvader's Avatar
    Join Date
    Oct 2000
    Location
    Glasgow-Scotland Forever
    Posts
    169
    In TCP/IP settings you can configure ports on your nic to only allow port 80 - that should help a bit.

    Its under TCP/IP Filtering in the advanced tab.

    Ideally wwwroot name should be changed and aliases used - our web files are on a separate server but a second disk or partition as you are using is always recommended - never install IIS/web on the system folder. Make sure all your web files are also 'r' only in the attributes for each file - every little bit helps.

    IIS lockdown tool is essential as is the windows c2 security tester.

    Better still - get linux - Just downloaded Redhat v8.0 5 cd's -took 5 days but it was worth it - Apache is fantastic.
    Last edited by bassinvader; 11-29-2002 at 09:26 PM.
    Sexual superstud of the new millenium...

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •