Hello OCUK,
I've woken up this morning to a notepad text file on the desktop of my home server named 'hacked.txt' which was placed there a little after 2am this morning and simply says 'secure your server idiot'....fair comment, they've got in, I cant argue.
Coincidentally, I formatted the Windows drive and completed a fresh Windows 10 install only a couple of days ago and have installed the bare minimum in respect of software all of which is paid/freeware (so no cracks/exploits to worry about). Having reviewed the event log, it appears that for several hours a script was attempting to gain access to my system via RDP generating multiple 'Audit Failures' trying to login in with multiple usernames SuperUser, admin, Rodgiro, Sara etc etc.
Previously i'll admit to being a little lapse on security, relying on Windows Defender. In attempt to re-secure my system I've done the following:
Are there any other steps you should suggest I take to further secure my system from hack attempts?
Many thanks
Russ
I've woken up this morning to a notepad text file on the desktop of my home server named 'hacked.txt' which was placed there a little after 2am this morning and simply says 'secure your server idiot'....fair comment, they've got in, I cant argue.
Coincidentally, I formatted the Windows drive and completed a fresh Windows 10 install only a couple of days ago and have installed the bare minimum in respect of software all of which is paid/freeware (so no cracks/exploits to worry about). Having reviewed the event log, it appears that for several hours a script was attempting to gain access to my system via RDP generating multiple 'Audit Failures' trying to login in with multiple usernames SuperUser, admin, Rodgiro, Sara etc etc.
Previously i'll admit to being a little lapse on security, relying on Windows Defender. In attempt to re-secure my system I've done the following:
- Installed Malware bytes, Avast Antivirus & Zone Alarm Firewall - run scans with all which have come up clear. Looks like my hacker might have just been experimenting?
- Removed all port forwards to my server from my router with the exception of one for Plex Media Server
- Setup an Open VPN server on my router to access my server remotely.
- Changed my RDP port from the default
- Changed system usernames and passwords
Are there any other steps you should suggest I take to further secure my system from hack attempts?
Many thanks
Russ