|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
From: James D. Stallard (cds
cionlne.com)Date: Thu Jan 10 2002 - 09:19:21 CST
Katherine
What is more worrying is how these machines were compromised in the
first place. I would do an audit of access to these machines and check
your firewalling and patch levels.
Good luck
James D. Stallard
-----Original Message-----
From: Katherine Ogden [mailto:kogden
4cd.net]
Sent: 10 January 2002 00:34
To: focus-ms
securityfocus.com
Subject: Think I've got trouble
We began having trouble with our exchange server.
For no reason we could pin down the OWA would
throw up an error and stop the www service. Being
the slightly paranoid sort I downloaded Retina and ran
it against the email server. It showed the usual things
but it also showed
Port 1058 - Nim
Port 1090 - Xtreme
Two other exchange servers show these ports open.
Port 1042 - Bla
Port 1059 - Nimreg
Two questions. Does anybody know what these
are? And am I right in assuming that these machines
have been compromised and will need to be rebuilt?
Thank you for the help.
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]