Microsoft "solves" hacking mystery
C|Net | at | by Mike
An advisory from the software giant last week warned companies of a number of attacks targeting servers running Windows 2000, the cause of which had initially puzzled Microsoft. After following a trail of evidence left behind on compromised Windows 2000 servers, the company now believes that hackers have systematically exploited Windows 2000 servers that haven't been properly locked down.
The attacks are linked by a common set of software detritus left behind to help an attacker keep control of compromised boxes. The most recent advisory warns that "successful compromises leave a distinctive pattern," including files identified as Backdoor.IRC.Flood and a modified security policy if the victim's computer is a domain controller. In addition, the hacked computers contain a common set of files, including Gg.bat, Seced.bat, Nt32.ini, Ocxdll.exe and Gates.txt. The file Gg.bat attempts to connect to other servers as an administrator or root user, while Seced.bat changes the security policy. Gates.txt contains a list of numerical Internet addresses; the advisory didn't offer details as to what the addresses may correspond.