A friend of mine was running a window's 2000 server with IIS enabled and was informed it was using too much bandwith and was beleived to be hacked. Has asked me to run a audit.Has been taken of line now.Don't know anything re IIS log files etc so any tips would help but here's what i came up with.Am i missing anything ??
FPORT
To map every open TCP and UDP port to a running executable.
2 Netstat -an to retrieve the conected IP addresses and opened port info. As it's off line not going to gain anything ??
3 Nbtstat -c Not much help as it's off line
4 PSLIST List processes on the machine.
5 Dir /a /t:a /o:d /s c:\ The a switch will list all files including hidden one's. The /t switch tells dir which time stamps you want to see. The /o:d switch tells the command you want it to be sorted by date.
6NTLAST Check's the logon and log off events and tells you when they where executed.
7 DUMPEL.
Retrieving the event log's
8 REGDMP which comes with NT/200 resource kit for dumping the registry into readable format.
This is going to be my first audit so will post later how i got on and the problem's i faced. :blink:
|
Page 1 of 1
Auditing Window's 2000 Procedure
#2
|
Our Sponsors: |

Sign In
Register
Help
MultiQuote

