Server Intrusion Prevention
Sunday, January 1, March 31, 2013
The WindowsServer2003 server hosted in the telecom data center is in the program test phase. Many people in the Administrator's account know that suspicious program network monitoring software has been found, but it cannot be determined whether hacker intrusion is detected, or installed by other administrators.
Log on to the Apsara stack console as administrator again on Sunday, January 1, March 31, 2013. The following message is displayed:
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; 615px; padding-right: 0px; height: 163px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image002 "border =" 0 "alt =" clip_image002 "src =" http://www.bkjia.com/uploads/allimg/131227/0A4103143-0.jpg "width =" 615 "height =" 163 "/>
Log in with the Administrator account zhang created yesterday and prompt that the password is incorrect.
Therefore, it is determined that the server has been hacked.
Now the Remote Desktop of the server is enabled, that is, Remote Desktop login cannot be used. Fortunately, the administrator password has not changed. How can I determine that the password has not changed?
When I use Windows Server 2003 to access Shared resources on the Server, I need to enter the Administrator account and password for accessing the Server.
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image003 "border =" 0 "alt =" clip_image003 "src =" http://www.bkjia.com/uploads/allimg/131227/0A4101J4-1.png "height =" 212 "/>
Enter the account and password, select remember my password, and enter the administrator account and password of the server to open the shared folder of the server. Therefore, it is determined that the password of the administrator user has not been changed after hacker intrusion. When you use a management tool to remotely manage the server, you do not need to enter the account and password.
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image004 "border =" 0 "alt =" clip_image004 "src =" http://www.bkjia.com/uploads/allimg/131227/0A4103141-2.png "height =" 285 "/>
Open the computer management tool on the Local Computer
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image006 "border =" 0 "alt =" clip_image006 "src =" http://www.bkjia.com/uploads/allimg/131227/0A410E18-3.jpg "height =" 385 "/>
Connect to another computer
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image008 "border =" 0 "hspace =" 12 "alt =" clip_image008 "src =" http://www.bkjia.com/uploads/allimg/131227/0A4105501-4.jpg "height =" 398 "/> enter IP address.
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image009 "border =" 0 "alt =" clip_image009 "src =" http://www.bkjia.com/uploads/allimg/131227/0A410LU-5.png "height =" 214 "/>
You can see that the connection is successful, but local users and groups cannot be remotely managed, and remote server services can be managed.
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image011 "border =" 0 "alt =" clip_image011 "src =" http://www.bkjia.com/uploads/allimg/131227/0A410D51-6.jpg "height =" 399 "/>
Follow these steps to enable the telnet service on the server,
Use telnet to recreate a new Administrator on the server
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image013 "border =" 0 "alt =" clip_image013 "src =" http://www.bkjia.com/uploads/allimg/131227/0A410J91-7.jpg "height =" 315 "/>
Telnet Remote Server
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image015 "border =" 0 "alt =" clip_image015 "src =" http://www.bkjia.com/uploads/allimg/131227/0A41054b-8.jpg "height =" 360 "/>
Enter y
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image017 "border =" 0 "alt =" clip_image017 "src =" http://www.bkjia.com/uploads/allimg/131227/0A4105C0-9.jpg "height =" 347 "/>
Enter the Administrator account and password of the server.
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image019 "border =" 0 "alt =" clip_image019 "src =" http://www.bkjia.com/uploads/allimg/131227/0A41040F-10.jpg "height =" 347 "/>
After remotely logging on to the server using telnet, run the following command to create the user wang password:
After adding the user to the Administrator group, the Administrator Group Name of the remote server has been changed to another name which is not the administrators. Now you need to determine the name of the remote server administrator group.
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image021 "border =" 0 "alt =" clip_image021 "src =" http://www.bkjia.com/uploads/allimg/131227/0A4103360-11.jpg "height =" 363 "/>
You can use the registry to view the names of users and groups on your computer. How can I open the remote server registry ?, You must enable the remote register Service.
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image023 "border =" 0 "alt =" clip_image023 "src =" http://www.bkjia.com/uploads/allimg/131227/0A4104428-12.jpg "height =" 316 "/>
Open Registry management tools locally.
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image024 "border =" 0 "alt =" clip_image024 "src =" http://www.bkjia.com/uploads/allimg/131227/0A41013D-13.png "height =" 172 "/>
The local registry is opened by default. Click the link to the network registry.
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; 643px; padding-right: 0px; height: 300px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image026 "border =" 0 "alt =" clip_image026 "src =" http://www.bkjia.com/uploads/allimg/131227/0A4103D7-14.jpg "width =" 643 "height =" 300 "/>
Enter the IP address of the server.
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image027 "border =" 0 "alt =" clip_image027 "src =" http://www.bkjia.com/uploads/allimg/131227/0A410L25-15.png "height =" 417 "/>
You can open the registry of a remote computer, but cannot open the SAM registry subkey. You need to change the permission.
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image028 "border =" 0 "alt =" clip_image028 "src =" http://www.bkjia.com/uploads/allimg/131227/0A4103524-16.png "height =" 398 "/>
Set the administrators group to full control
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image029 "border =" 0 "alt =" clip_image029 "src =" http://www.bkjia.com/uploads/allimg/131227/0A410CF-17.png "height =" 417 "/>
Press F5 to refresh and expand SAM
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image030 "border =" 0 "alt =" clip_image030 "src =" http://www.bkjia.com/uploads/allimg/131227/0A41024M-18.png "height =" 401 "/>
As shown in, the Administrator group has been changed to administraters
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image031 "border =" 0 "alt =" clip_image031 "src =" http://www.bkjia.com/uploads/allimg/131227/0A410Hb-19.png "height =" 530 "/>
Confirm the name of the Administrator group, use telnet to log on to the server, and add the created user to the Administrator group.
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image033 "border =" 0 "alt =" clip_image033 "src =" http://www.bkjia.com/uploads/allimg/131227/0A410B17-20.jpg "height =" 168 "/>
Now, remotely connect to the server using the newly created administrator.
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image034 "border =" 0 "alt =" clip_image034 "src =" http://www.bkjia.com/uploads/allimg/131227/0A4101245-21.png "height =" 252 "/>
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image035 "border =" 0 "alt =" clip_image035 "src =" http://www.bkjia.com/uploads/allimg/131227/0A4103013-22.png "height =" 233 "/>
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image037 "border =" 0 "alt =" clip_image037 "src =" http://www.bkjia.com/uploads/allimg/131227/0A41060C-23.jpg "height =" 398 "/>
Login successful
Open the computer management tool and you will see no user management
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image039 "border =" 0 "alt =" clip_image039 "src =" http://www.bkjia.com/uploads/allimg/131227/0A41060C-24.jpg "height =" 397 "/>
Install 360 anti-virus software, install 360 security guard for scanning, and find stubborn viruses and problems to be fixed.
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image041 "border =" 0 "alt =" clip_image041 "src =" http://www.bkjia.com/uploads/allimg/131227/0A4105K4-25.jpg "height =" 291 "/>
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image043 "border =" 0 "alt =" clip_image043 "src =" http://www.bkjia.com/uploads/allimg/131227/0A4101945-26.jpg "height =" 419 "/>
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image045 "border =" 0 "alt =" clip_image045 "src =" http://www.bkjia.com/uploads/allimg/131227/0A4105b9-27.jpg "height =" 347 "/>
Not finished yet !!!!!!!
Advertisement
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; 754px; padding-right: 0px; height: 300px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image001 [6] "border =" 0 "alt =" clip_image001 [6] "src =" http://www.bkjia.com/uploads/allimg/131227/0A4104V2-28.jpg "width =" 754 "height =" 300 "/>
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; 755px; padding-right: 0px; height: 300px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image002 [6] "border =" 0 "alt =" clip_image002 [6] "src =" http://www.bkjia.com/uploads/allimg/131227/0A410F39-29.jpg "width =" 755 "height =" 300 "/>
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; 753px; padding-right: 0px; height: pixel PX; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image003 [6] "border =" 0 "alt =" clip_image003 [6] "src =" http://www.bkjia.com/uploads/allimg/131227/0A4103323-30.jpg "width =" 753 "height =" 347 "/>
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; 758px; padding-right: 0px; height: pixel PX; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image004 [7] "border =" 0 "alt =" clip_image004 [7] "src =" http://www.bkjia.com/uploads/allimg/131227/0A41011S-31.jpg "width =" 758 "height =" 465 "/>
This article from "Han Li Gang" blog, please be sure to keep this source http://91xueit.blog.51cto.com/400469/1168081