IWETHEY v. 0.3.0 | TODO
1,095 registered users | 0 active users | 0 LpH | Statistics
Login | Create New User
IWETHEY Banner

Welcome to IWETHEY!

New Compromised server
Small Business client has a Windows 2000 server running one client-server program, Syspro accounting. No other use except to back up payroll files from a PC so they back up to tape. D: shared, C: not shared.

Network has a Linksys router with port forwarding for Terminal Services only.

Windows 98 SE workstations on the network started blue screening yesterday when they tried to print reports or invoice from Syspro accounting.

I took a look at the router and it had heavy Internet traffic - all originating from the server. Fresh installs and updates of anti-virus and Adaware - scans showed nothing - totally clean. Workstations also clean. LSPFix showed a custom module in the protocol stack, and when I removed it Internet traffic stopped.

Reinstalled Windows 2000. Loaded all updates and patches. Uninstalled and reinstalled Terminal Services due to errors in the system log. Fresh install of anti-virus - scans still show nothing - clean.

Windows 98 SE workstations now print from Syspro without blue screening.

Possible entry point, a Vice President's notebook from which I often have to remove worms, trojans and spyware. Windows/Internet problems continue to grow.
[link|http://www.aaxnet.com|AAx]
New Re: Linksys router.
They have been know to be vulnerable in the past.

[link|http://cert.uni-stuttgart.de/archive/bugtraq/2002/11/msg00269.html|Example].

It wouldn't hurt to check the firmware level and, if needed, update it.
Alex

The trouble with the world is that the stupid are cocksure and the intelligent are full of doubt. -- Bertrand Russell
New It's only a couple of months old, and . . .
. . remote management is turned off. There's nobody on the inside who has any idea what a router is, never mind how to access one.

I'm aware of the flaw in the older routers, but the same is true for all my installations - no remote access, nobody inside who knows what a router is (except that it is blue and should be power cycled along with the bridge if you don't have internet access).
[link|http://www.aaxnet.com|AAx]
     Compromised server - (Andrew Grygus) - (2)
         Re: Linksys router. - (a6l6e6x) - (1)
             It's only a couple of months old, and . . . - (Andrew Grygus)

Welcome to those that can stand it.
66 ms