Win 2003 Server Take lots of bandwith over weekends?

Viruses, hackers and crackers
Post Reply
TheWall
Registered User
Posts: 23
Joined: 09 Mar 2004, 02:00
Location: Midrand
Contact:

Win 2003 Server Take lots of bandwith over weekends?

Post by TheWall »

Hi

I have a Win2003 server with SQL 2000 installed.

Over weekends it take half of the bandwith. I have Scanned it with symantec corporate edition and lots of virus fixes... none of it picked up anything. I traced all the outgoing packets and loads of the went to different IP Addresses(which follewed on each other) but all to port 1433, which is a SQL Port. any help or ideas please?
Thinice
Registered User
Posts: 360
Joined: 08 Jul 2002, 02:00
Contact:

Post by Thinice »

Are there any logs in the event viewer???

I am also running Windows 2003 with SQL 2000, I will check mine as well
Thrall
Moderator Emeritus
Posts: 3687
Joined: 30 Apr 2003, 02:00
Location: Texas, USA

Post by Thrall »

I'm not an SQL boffin, but I know there are a number of worms which attack default installations of SQL server - typically those with blank sa passwords - and send out probes on port 1433 and 1434.

Slammer, Spida, DigiSpid are all examples from almost a year ago, so unless your AV defenitions are seriously out-of-date, you may have a new nasty onboard.

Maybe this link will come in handy - I'd also suggest a firewall.

What processes are running, by the way?
Be polite, professional and have a plan to kill everyone you meet.

My Iraq pics
TheWall
Registered User
Posts: 23
Joined: 09 Mar 2004, 02:00
Location: Midrand
Contact:

Post by TheWall »

Well i have ran fixes for SQLSnake, SQL Slammer and a few of them. Going to gave a look in the event viewer when i get a chance. All the latest service packs and fixes is installed. Think im gotta have to install a firewall... that should do the job... for processes go have a look at

http://www.dyntek.co.za under virus help. the's a xls file called processes
Thrall
Moderator Emeritus
Posts: 3687
Joined: 30 Apr 2003, 02:00
Location: Texas, USA

Post by Thrall »

I don't see anything which jumps out at me in there - all seem legit but could have been replaced by a trojaned version, I guess. The port-traffic you mentioned worries me, though - use a packet-sniffer and see what the traffic consists of.

Edit: Anything weird on startup in the registry?
Be polite, professional and have a plan to kill everyone you meet.

My Iraq pics
TheWall
Registered User
Posts: 23
Joined: 09 Mar 2004, 02:00
Location: Midrand
Contact:

Post by TheWall »

where can i get a packet sniffer?
TheWall
Registered User
Posts: 23
Joined: 09 Mar 2004, 02:00
Location: Midrand
Contact:

Post by TheWall »

here is a link to a diagram of the trafic. green bit is outgoing trafic all always happen at night or over weekends http://www.dyntek.co.za/webshack-week.png
Thrall
Moderator Emeritus
Posts: 3687
Joined: 30 Apr 2003, 02:00
Location: Texas, USA

Post by Thrall »

TheWall wrote:where can i get a packet sniffer?
Here's a basic Windows sniffer - only a trial-version, but it'll check outbound packets.

Here's another one
Be polite, professional and have a plan to kill everyone you meet.

My Iraq pics
TheWall
Registered User
Posts: 23
Joined: 09 Mar 2004, 02:00
Location: Midrand
Contact:

Post by TheWall »

have installed it now just have to wait for the thing to start again. Think im gonna install the firewall anyway.
Post Reply