The Cellar  

Go Back   The Cellar > Main > Technology
FAQ Community Calendar Today's Posts Search

Technology Computing, programming, science, electronics, telecommunications, etc.

 
 
Thread Tools Display Modes
Prev Previous Post   Next Post Next
Old 05-08-2002, 11:15 AM   #1
Undertoad
Radical Centrist
 
Join Date: Jan 2001
Location: Cottage of Prussia
Posts: 31,423
Win2K security = 0

Granted I'm no MCSE, but...

All I did...

I loaded Win 2K on an empty machine.

I did a Windows Update and retrieved and applied all the patches.

I set a pretty strong Administrator password, and set up requiring ctrl-alt-del to log in.

I set up one non-Admin user for FTP access.

I started IIS and FTP. I did development work on the box for three weeks.

I notice some odd unexpected inbound traffic. Check it out and indeed, the box has been cracked. Somebody's put some warez into the non-Admin user's FTP section.

Now, granted FTP uses plain-text passwords, and granted I don't use a hardware firewall here, and granted a whole bunch of other stuff. But three weeks! Come on!
Undertoad is offline   Reply With Quote
 


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

All times are GMT -5. The time now is 10:43 AM.


Powered by: vBulletin Version 3.8.1
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.