JaffaB
2012-08-01 11:07:00 UTC
Hi all,
I have a problem. This morning, somebody tried to hack my SBS2003 server.
Somehow, they managed to remotely create a new ADMIN user and login use RDC to this user. I have SBS server scripts which alerted me that the user had been created, a user had tried to log in, but then the server kicked them off (I then deleted the account).
I have RDC set on only 3 user accounts - and nobody accessed these accounts. I have very strong passwords on all user accounts and would have been notified if they got through and RDC'd/logged in to any of these accounts?
So how did they manage to create this account? Could they have done it through SQL or something? Really confused (and concerned).
Any help or suggestions would be appreciated.
I have a problem. This morning, somebody tried to hack my SBS2003 server.
Somehow, they managed to remotely create a new ADMIN user and login use RDC to this user. I have SBS server scripts which alerted me that the user had been created, a user had tried to log in, but then the server kicked them off (I then deleted the account).
I have RDC set on only 3 user accounts - and nobody accessed these accounts. I have very strong passwords on all user accounts and would have been notified if they got through and RDC'd/logged in to any of these accounts?
So how did they manage to create this account? Could they have done it through SQL or something? Really confused (and concerned).
Any help or suggestions would be appreciated.