Forum Moderators: phranque
I am the only user on the server. I tried to look at the event log and I didn't find anything particularly suspicious. There are a few FTP failed attempts though.
Is there anywhere I should look? What could have caused this? Is this an hack attempt on my server, and theirs?
Any help is greatly appreciated. Thank you.
port 1521 seems to be common for oracle listener services, though in the port list [iana.org] it is 'nCube License Manager'
those two things might be something to look at
Have you heard of this Exploit-DFind before? I am not sure if I should do a server reload (Partly because I don't really want the server to go down for unknown hours because I am in the middle of a big advertising campaign). I hope no other system files were corrupted.
When deploying a web server just block any outbound ports you dont use to limit your liability.
Most web servers should never need to initiate an outbound session other than for AV/Windows updates etc, which are to known IP's, so you can pretty much block all outbound ports without losing any functionality.