Re: Corrupted Directories, Intrusions, and Nimda Oh MY

From: H C (keydet89at_private)
Date: Fri Nov 09 2001 - 03:54:31 PST

  • Next message: Joerg Over: "Re: SYN Flood attack with sequential destination ports?"

    Drew,
    
    > > Went on vacation for a week, come back to see that
    > my email server is
    > > reporting that its comepletely full. Look a little
    > deeper into it and I
    > > see that people have uploaded tons of MP3's,
    > Warez, etc.. 
    
    Sounds like this was more than an email server. 
    Sounds like it had IIS and FTP running as well.  What
    you describe is indicative of the FTP server being
    configured so that the anonymous user has write access
    to the drive.
    
    > Anyone got a tool that
    > > will allow me to just delete the directory and all
    > the subdirectories
    > > this stuff is in? 
    
    Have you tried "rmdir /s" ?  Also, 'del' or 'erase'
    with the /F switch looks like they might be helpful.
    
    
    
    
    __________________________________________________
    Do You Yahoo!?
    Find a job, post your resume.
    http://careers.yahoo.com
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Fri Nov 09 2001 - 08:58:00 PST