Groups | Blog | Home
all groups > iis security > september 2004 >

iis security : How to remove the backdoor codes left by EX engineer



Jack
9/29/2004 12:26:04 PM
Our Ex engineer left some backdoor code into our web
server and he attacked the server 3 times already via his
backdoor codes. He formated all our data after he broke
into our server every time.

Our server is Windows 2K server and SQL server 2K. Our
web server is ASP based with some VJ compiled DLL files.

We do have all source code for those VJ DLL files. How
can we remove those backdoor code? Any web sites provide
helpful information about this issue?

Thanks for your support,
Dave
9/29/2004 7:51:23 PM
you hire a new engineer who is better than he was to find it all and dig it
out and prove what he did. and if he really did it you start by filing a
criminal complaint and get him thrown in jail. then sue the pants off him
for damages.

[quoted text, click to view]

Miha Pihler
9/29/2004 9:59:46 PM
With all the services running (e.g. SQL, IIS) I would also check the setup
configuration. Is SQL patched and secured. Is IIS patched and secured (e.g.
on IIS5 is IISLockDown and URL Scan installed). Are Windows patched and
secured. Etc...

Mike

[quoted text, click to view]

jeff.nospam NO[at]SPAM zina.com
9/29/2004 11:55:59 PM
On Wed, 29 Sep 2004 12:26:04 -0700, "Jack"
[quoted text, click to view]

1) Depending on your country, have your Ex jailed.

2) Flattent he box and reinstall from scratch, using only known good
data and none of his DLL files.

3) Rewrite your own DLL's.

4) Did I mention that even if he's jailed you can sue his ass...?

5) Some help at securityadmin.info, but not for coding issues.

You'll need to rewrite and recompile the DLL's, and have someone who
knows what they're doing go over the code line by line.

AddThis Social Bookmark Button