SBS 2003 Security

Associate
Joined
16 Dec 2003
Posts
1,586
Location
Halifax , UK
Over the past few weeks we've had two unwanted connections to our SBS 2003 box, in that without us knowing someone is connecting through remote desktop, being able to successfully log in and then do some of the following:

- Create new Admin accounts
- Remove Software
- Install Software

We are only noticing this when we see software has altered or new users have appeared in Active Directory Users & Computers.

We've changed all domain admin account passwords and thoroughly scanned the server for Malware/Viruses when this first happened but its happened again over the past few days.

My next step was going to be to disable the built in administrator account.

Any more thoughts on what this could be or how to stop it?

Thanks!
 
Server fully patched, we have RD port 3389 forwarded to the server through the router.

We really need a remote RD connection for support, I'll change the RD port in the registry to something other than 3389.
 
It does yes, but RD will be listening on 3389 so as soon as this user tries to connect they will be able to connect, if I change the RD port they have no way of knowing what the port has been changed to?
 
Back
Top Bottom