nothing very important, and yes, that'll be a last resort.
this is a friend's server.... its been hacked before due to him not patching (and caught the SQL Slammer worm).
i did manage to kill the ServU process via the "services.msc" panel. i deleted the .exe files associated and fucked with the configuration files (.ini) to change the cracker's passwords and shit.
it's pretty scary stuff. i guess once this shit's running, you can remotely monitor stuff via the web. you can even search out the infected machines by looking up this file:
|rwamelcdp
serv-u is apparently "legit" ftp software just used crack machines and set up all kinds of shit.
__________________
aaarrrrrgggghhhh!!!!
Last edited by soopafreek; 07-06-2004 at 10:19 PM..
|