My DC and Domain User`s Password Was Hacked


hi,


recently find out when run query on  my  active directory and  dsa.msc on primary dc take long time run  , after days  one person claimed dc hacked him . tell me till each user change password can see new password online on application ,i think use pass hash method  or use periodic query dc high user privilege.

i dont know name of application , way can see user`s password change on active directory?

i changed domain administrator password , told me new password.

i use microsoft tcp/view , microsoft processed explorer , did not see suspicious process , seems ok ,i use tcp view show s lots of tcp connection client machine , server .

i dont know how solve problem , fin out how hacked , see domain user`s password.

i want stop him , solve problem.

you kind enough if helping me?

regard


hi samuel_emi,

firstly found computer has hacked must backup important data isolate , cut off network connection because may infect others computer, far know there don’t have method user password ad, assume client computer has injected trojan virus, when client user change his/she password new password recorded, personal suggest must disable account , isolate computer or reinstall system.

you must recovery current dc update av soft scan computer in corp.

more related kb:

help: got hacked. do?

http://technet.microsoft.com/en-us/library/cc512587.aspx

hope helps.


we trying better understand customer views on social support experience, participation in interview project appreciated if have time.
helping make community forums great place.



Windows Server  >  Security



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file