1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Other Remote Desktop'd to my server/nas, saw someone using it (hacker)

Discussion in 'Software' started by Gurdeep14, 12 Oct 2014.

  1. Gurdeep14

    Gurdeep14 Minimodder

    Joined:
    25 Apr 2009
    Posts:
    650
    Likes Received:
    26
    Hi guys
    This is worrying me. I have a server/nas I built running windows 8.1 64 bit professional, it is always on 24/7.
    Every few days I remote desktop to it to see if everything is running ok and check for updates etc. Tonight I connected to it and got a message a user was connected and they were disconnected so I could connect.
    Once it established a connection, I saw a cmd window running with some IP related commands running and a webpage open, a few seconds later I was disconnected again as the hacker connected back to the server. I once again connected again (1 second later) to disconnect him (this happened a 3 times)
    Then I connected and right clicked My Computer and disabled Allow Remote Connections and enabled Remote Desktop with Network Level Authentication. After that, the hacker didn't connect back (not sure if that stopped him or he realised he got found out and quit)
    Theses options were originally unselected due to Microsoft support working on the Server a few weeks back (updates werent working)

    This was really worrying. I was only using Microsoft Defender (for AV) and Windows Firewall (thinking i'd never need anything more.
    I checked the open webpage, it was some french site, and checked the history, the hacker had been using the internet browser for around 40 minutes, running a speed test, going to a website to figure out my IP address, going to VPNs and Proxies and then eventually....Porn? WTF
    I think he was either french or spanish judging by the sites he visited.

    After this, I signed out of Chrome, and did a system restore to a few days before to remove any registry changed he may have made.
    I then installed Private Firewall 7.0 and and currently running a virus scan (it runs automatically every night at 3am anyway)
    Should I be worried? Any ideas or help?

    Thanks guys
     
  2. deathtaker27

    deathtaker27 Modder

    Joined:
    17 Apr 2010
    Posts:
    2,238
    Likes Received:
    186
    Have you got 3389 external mapped to your internal server?

    If so is it locked down to a range of ip addresses or anyone on your router?
    And change your password
     
  3. Gurdeep14

    Gurdeep14 Minimodder

    Joined:
    25 Apr 2009
    Posts:
    650
    Likes Received:
    26
    I literally have no idea what that means. Im not totally clued up with networks. I have my router set to MAC address filtering & I have a limited IP range (the exact amount of devices in my network).
    Other than that, I have done nothing else.
    Could you talk me through what you mean please
    thanks
     
  4. Gurdeep14

    Gurdeep14 Minimodder

    Joined:
    25 Apr 2009
    Posts:
    650
    Likes Received:
    26
    Just changed the password for the server and deleted the Port Forwarding rule I had in place for port 3389 from the router. Is that what you meant?
     
  5. Pookie

    Pookie Illegitimi non carborundum

    Joined:
    4 May 2010
    Posts:
    3,565
    Likes Received:
    175
    That will stop the remote access Gurdeep not only for the hacker but also for you. If I was you I would do the following...

    1. Change the default port used for RDP. Use a obscure port like 50578. http://support2.microsoft.com/kb/306759 When you connect via remote desktop you will need to format the address like this 85.67.123.16:50578

    2. Make sure you do not use the default "Administrator" account. I would disable this and create a new admin account using a name that's hard to guess.

    3. Contact your ISP and see if you can get a new static IP address. They should be able to help you with this.

    Good luck
     
  6. Gurdeep14

    Gurdeep14 Minimodder

    Joined:
    25 Apr 2009
    Posts:
    650
    Likes Received:
    26
    Thanks for the reply Pookie :)
    I changed the Port over on the server and turned the server/nas off and on and now I cant connect to the server. I added an exception in the router for the port and I tried connecting via RDP using the 192.168.0.*:new port number but that didn't work. I also tried doing the same with the external IP address without luck. Any ideas? Anything obvious I am missing?
     
  7. Pookie

    Pookie Illegitimi non carborundum

    Joined:
    4 May 2010
    Posts:
    3,565
    Likes Received:
    175
    Dont forget you will need to port forward your new port in the router.
     
  8. Gurdeep14

    Gurdeep14 Minimodder

    Joined:
    25 Apr 2009
    Posts:
    650
    Likes Received:
    26
    I have, I set it as TCP/UPD, that didnt help.
    Could it be the windows firewall on the server/nas?
     
  9. Pookie

    Pookie Illegitimi non carborundum

    Joined:
    4 May 2010
    Posts:
    3,565
    Likes Received:
    175
    Ah yes. It's too early lol. In and out rule required on the windows firewall.
     
  10. Votick

    Votick My CPU's hot but my core runs cold.

    Joined:
    21 May 2009
    Posts:
    2,321
    Likes Received:
    109
    TBH I would have done Port Translation on the router from the external port to the internal on 3389.
     
  11. creative

    creative 500rwhp

    Joined:
    23 May 2014
    Posts:
    586
    Likes Received:
    65
    Did you contact MS or did they contact you?
     
  12. Gurdeep14

    Gurdeep14 Minimodder

    Joined:
    25 Apr 2009
    Posts:
    650
    Likes Received:
    26
    I contacted them. They made me use logmein (I think, it didn't install, it just ran from the .exe.)
     
  13. Gurdeep14

    Gurdeep14 Minimodder

    Joined:
    25 Apr 2009
    Posts:
    650
    Likes Received:
    26
    Done that and it now works again :)
    Thanks Pookie

    I also ran Microsoft Baseline Security Analyzer and made and necessary changes. Anything else you guys can suggest? Is it worth buying a dedicated firewall/VPN to put before the router (Netgear WND3700)?
     
  14. ModSquid

    ModSquid Multimodder

    Joined:
    16 Apr 2011
    Posts:
    2,636
    Likes Received:
    832
    I asked a similar question a while back as I was nervous about opening myself up during online gaming and someone suggested using this site:

    https://www.grc.com/shieldsup

    Apologies to whomever it was as I can't remember. I haven't used it myself yet though, so have nothing to go by unfortunately.
     
  15. Gurdeep14

    Gurdeep14 Minimodder

    Joined:
    25 Apr 2009
    Posts:
    650
    Likes Received:
    26
    Thanks for that site, it really helped show me which ports were vulnerable. Since then I have changed routers to a Netgear Nighthawk R7000. It seems to be much more secure, with ALL ports stealthed.
     
  16. Gurdeep14

    Gurdeep14 Minimodder

    Joined:
    25 Apr 2009
    Posts:
    650
    Likes Received:
    26
    According to my new router logs (Netgear Nighthawk) I have been targeted for a lot of attacks.
    I am considering a RADIUS server, if it would help? Perhaps on a Raspberry Pi

     
  17. Gareth Halfacree

    Gareth Halfacree WIIGII! Lover of bit-tech Administrator Super Moderator Moderator

    Joined:
    4 Dec 2007
    Posts:
    17,130
    Likes Received:
    6,719
    Those are almost all internal IP addresses; you're not being targeted, and are not under active attack. The traffic the 'firewall' is (incorrectly, by the look of things) triggering on is coming from your internal network, not the internet. Assuming you've checked the hosts for malicious software, then you've nothing to fear: it's just yet another instance of a consumer-grade 'firewall' making a lot of noise about nothing to reassure you that your money wasn't wasted.
    I wouldn't advise this.
     
  18. modd1uk

    modd1uk Multimodder

    Joined:
    4 Sep 2006
    Posts:
    3,554
    Likes Received:
    447
    Damn those 192. hackers.
     
  19. Gurdeep14

    Gurdeep14 Minimodder

    Joined:
    25 Apr 2009
    Posts:
    650
    Likes Received:
    26
    there are some foreign IP addresses.
    [DoS attack: ACK Scan] attack packets in last 20 sec from ip [208.64.202.85], Thursday, Nov 27,2014 14:46:27
    [DoS attack: ACK Scan] attack packets in last 20 sec from ip [208.64.202.85], Thursday, Nov 27,2014 14:45:34
    [DoS attack: FIN Scan] attack packets in last 20 sec from ip [173.194.67.95], Friday, Nov 28,2014 17:45:00
    [DoS attack: STORM] attack packets in last 20 sec from ip [141.134.78.191], Saturday, Nov 29,2014 19:32:17
    [DoS attack: STORM] attack packets in last 20 sec from ip [141.134.78.191], Saturday, Nov 29,2014 19:31:56
    [DoS attack: STORM] attack packets in last 20 sec from ip [81.233.177.223], Saturday, Nov 29,2014 19:31:22
    [DoS attack: STORM] attack packets in last 20 sec from ip [81.155.202.10], Saturday, Nov 29,2014 19:28:18
    [DoS attack: STORM] attack packets in last 20 sec from ip [94.2.235.209], Saturday, Nov 29,2014 19:23:21
    [DoS attack: STORM] attack packets in last 20 sec from ip [94.2.235.209], Saturday, Nov 29,2014 19:22:58
    [DoS attack: STORM] attack packets in last 20 sec from ip [151.228.57.252], Saturday, Nov 29,2014 19:20:36
     
  20. Gareth Halfacree

    Gareth Halfacree WIIGII! Lover of bit-tech Administrator Super Moderator Moderator

    Joined:
    4 Dec 2007
    Posts:
    17,130
    Likes Received:
    6,719
    That's why I said 'almost all.' I repeat: you are not being targeted, you are not under attack. What you're seeing is just a normal day on the internet. Stop poring over the 'firewall' logs; you will never see anything useful in there, I can guarantee it.
     

Share This Page