My DC and Domain User`s Password Was Hacked
hi,
recently find out when run query on my active directory and dsa.msc on primary dc take long time run , after days one person claimed dc hacked him . tell me till each user change password can see new password online on application ,i think use pass hash method or use periodic query dc high user privilege.
i dont know name of application , way can see user`s password change on active directory?
i changed domain administrator password , told me new password.
i use microsoft tcp/view , microsoft processed explorer , did not see suspicious process , seems ok ,i use tcp view show s lots of tcp connection client machine , server .
i dont know how solve problem , fin out how hacked , see domain user`s password.
i want stop him , solve problem.
you kind enough if helping me?
regard
hi samuel_emi,
firstly found computer has hacked must backup important data isolate , cut off network connection because may infect others computer, far know there don’t have method user password ad, assume client computer has injected trojan virus, when client user change his/she password new password recorded, personal suggest must disable account , isolate computer or reinstall system.
you must recovery current dc update av soft scan computer in corp.
more related kb:
help: got hacked. do?
http://technet.microsoft.com/en-us/library/cc512587.aspx
hope helps.
Windows Server > Security
Comments
Post a Comment