Server Intrusion Prevention

Source: Internet
Author: User

Server Intrusion Prevention

Sunday, January 1, March 31, 2013

The WindowsServer2003 server hosted in the telecom data center is in the program test phase. Many people in the Administrator's account know that suspicious program network monitoring software has been found, but it cannot be determined whether hacker intrusion is detected, or installed by other administrators.

Log on to the Apsara stack console as administrator again on Sunday, January 1, March 31, 2013. The following message is displayed:

650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; 615px; padding-right: 0px; height: 163px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image002 "border =" 0 "alt =" clip_image002 "src =" http://www.bkjia.com/uploads/allimg/131227/0A4103143-0.jpg "width =" 615 "height =" 163 "/>

Log in with the Administrator account zhang created yesterday and prompt that the password is incorrect.

Therefore, it is determined that the server has been hacked.

Now the Remote Desktop of the server is enabled, that is, Remote Desktop login cannot be used. Fortunately, the administrator password has not changed. How can I determine that the password has not changed?

When I use Windows Server 2003 to access Shared resources on the Server, I need to enter the Administrator account and password for accessing the Server.

650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image003 "border =" 0 "alt =" clip_image003 "src =" http://www.bkjia.com/uploads/allimg/131227/0A4101J4-1.png "height =" 212 "/>

Enter the account and password, select remember my password, and enter the administrator account and password of the server to open the shared folder of the server. Therefore, it is determined that the password of the administrator user has not been changed after hacker intrusion. When you use a management tool to remotely manage the server, you do not need to enter the account and password.

650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image004 "border =" 0 "alt =" clip_image004 "src =" http://www.bkjia.com/uploads/allimg/131227/0A4103141-2.png "height =" 285 "/>

Open the computer management tool on the Local Computer

650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image006 "border =" 0 "alt =" clip_image006 "src =" http://www.bkjia.com/uploads/allimg/131227/0A410E18-3.jpg "height =" 385 "/>

Connect to another computer

650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image008 "border =" 0 "hspace =" 12 "alt =" clip_image008 "src =" http://www.bkjia.com/uploads/allimg/131227/0A4105501-4.jpg "height =" 398 "/> enter IP address.

650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image009 "border =" 0 "alt =" clip_image009 "src =" http://www.bkjia.com/uploads/allimg/131227/0A410LU-5.png "height =" 214 "/>

You can see that the connection is successful, but local users and groups cannot be remotely managed, and remote server services can be managed.

650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image011 "border =" 0 "alt =" clip_image011 "src =" http://www.bkjia.com/uploads/allimg/131227/0A410D51-6.jpg "height =" 399 "/>

Follow these steps to enable the telnet service on the server,

Use telnet to recreate a new Administrator on the server

650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image013 "border =" 0 "alt =" clip_image013 "src =" http://www.bkjia.com/uploads/allimg/131227/0A410J91-7.jpg "height =" 315 "/>

Telnet Remote Server

650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image015 "border =" 0 "alt =" clip_image015 "src =" http://www.bkjia.com/uploads/allimg/131227/0A41054b-8.jpg "height =" 360 "/>

Enter y

650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image017 "border =" 0 "alt =" clip_image017 "src =" http://www.bkjia.com/uploads/allimg/131227/0A4105C0-9.jpg "height =" 347 "/>

Enter the Administrator account and password of the server.

650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image019 "border =" 0 "alt =" clip_image019 "src =" http://www.bkjia.com/uploads/allimg/131227/0A41040F-10.jpg "height =" 347 "/>

After remotely logging on to the server using telnet, run the following command to create the user wang password:

After adding the user to the Administrator group, the Administrator Group Name of the remote server has been changed to another name which is not the administrators. Now you need to determine the name of the remote server administrator group.

650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image021 "border =" 0 "alt =" clip_image021 "src =" http://www.bkjia.com/uploads/allimg/131227/0A4103360-11.jpg "height =" 363 "/>

You can use the registry to view the names of users and groups on your computer. How can I open the remote server registry ?, You must enable the remote register Service.

650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image023 "border =" 0 "alt =" clip_image023 "src =" http://www.bkjia.com/uploads/allimg/131227/0A4104428-12.jpg "height =" 316 "/>

Open Registry management tools locally.

650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image024 "border =" 0 "alt =" clip_image024 "src =" http://www.bkjia.com/uploads/allimg/131227/0A41013D-13.png "height =" 172 "/>

The local registry is opened by default. Click the link to the network registry.

650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; 643px; padding-right: 0px; height: 300px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image026 "border =" 0 "alt =" clip_image026 "src =" http://www.bkjia.com/uploads/allimg/131227/0A4103D7-14.jpg "width =" 643 "height =" 300 "/>

Enter the IP address of the server.

650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image027 "border =" 0 "alt =" clip_image027 "src =" http://www.bkjia.com/uploads/allimg/131227/0A410L25-15.png "height =" 417 "/>

You can open the registry of a remote computer, but cannot open the SAM registry subkey. You need to change the permission.

650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image028 "border =" 0 "alt =" clip_image028 "src =" http://www.bkjia.com/uploads/allimg/131227/0A4103524-16.png "height =" 398 "/>

Set the administrators group to full control

650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image029 "border =" 0 "alt =" clip_image029 "src =" http://www.bkjia.com/uploads/allimg/131227/0A410CF-17.png "height =" 417 "/>

Press F5 to refresh and expand SAM

650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image030 "border =" 0 "alt =" clip_image030 "src =" http://www.bkjia.com/uploads/allimg/131227/0A41024M-18.png "height =" 401 "/>

As shown in, the Administrator group has been changed to administraters

650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image031 "border =" 0 "alt =" clip_image031 "src =" http://www.bkjia.com/uploads/allimg/131227/0A410Hb-19.png "height =" 530 "/>

Confirm the name of the Administrator group, use telnet to log on to the server, and add the created user to the Administrator group.

650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image033 "border =" 0 "alt =" clip_image033 "src =" http://www.bkjia.com/uploads/allimg/131227/0A410B17-20.jpg "height =" 168 "/>

Now, remotely connect to the server using the newly created administrator.

650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image034 "border =" 0 "alt =" clip_image034 "src =" http://www.bkjia.com/uploads/allimg/131227/0A4101245-21.png "height =" 252 "/>

650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image035 "border =" 0 "alt =" clip_image035 "src =" http://www.bkjia.com/uploads/allimg/131227/0A4103013-22.png "height =" 233 "/>

650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image037 "border =" 0 "alt =" clip_image037 "src =" http://www.bkjia.com/uploads/allimg/131227/0A41060C-23.jpg "height =" 398 "/>

Login successful

Open the computer management tool and you will see no user management

650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image039 "border =" 0 "alt =" clip_image039 "src =" http://www.bkjia.com/uploads/allimg/131227/0A41060C-24.jpg "height =" 397 "/>

Install 360 anti-virus software, install 360 security guard for scanning, and find stubborn viruses and problems to be fixed.

650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image041 "border =" 0 "alt =" clip_image041 "src =" http://www.bkjia.com/uploads/allimg/131227/0A4105K4-25.jpg "height =" 291 "/>

650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image043 "border =" 0 "alt =" clip_image043 "src =" http://www.bkjia.com/uploads/allimg/131227/0A4101945-26.jpg "height =" 419 "/>

650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image045 "border =" 0 "alt =" clip_image045 "src =" http://www.bkjia.com/uploads/allimg/131227/0A4105b9-27.jpg "height =" 347 "/>

Not finished yet !!!!!!!

Advertisement

650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; 754px; padding-right: 0px; height: 300px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image001 [6] "border =" 0 "alt =" clip_image001 [6] "src =" http://www.bkjia.com/uploads/allimg/131227/0A4104V2-28.jpg "width =" 754 "height =" 300 "/>

650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; 755px; padding-right: 0px; height: 300px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image002 [6] "border =" 0 "alt =" clip_image002 [6] "src =" http://www.bkjia.com/uploads/allimg/131227/0A410F39-29.jpg "width =" 755 "height =" 300 "/>

650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; 753px; padding-right: 0px; height: pixel PX; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image003 [6] "border =" 0 "alt =" clip_image003 [6] "src =" http://www.bkjia.com/uploads/allimg/131227/0A4103323-30.jpg "width =" 753 "height =" 347 "/>

650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; 758px; padding-right: 0px; height: pixel PX; border-top: 0px; border-right: 0px; padding-top: 0px "title =" clip_image004 [7] "border =" 0 "alt =" clip_image004 [7] "src =" http://www.bkjia.com/uploads/allimg/131227/0A41011S-31.jpg "width =" 758 "height =" 465 "/>

This article from "Han Li Gang" blog, please be sure to keep this source http://91xueit.blog.51cto.com/400469/1168081

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.