A
arachnidservice
Guest
Greetings, Im currently using a windows 2003 server with plesk, i've been tightning up the security on the server to ensure it does not get compromised, etc.
I installed a program called tcpview from sysinternals, which allows me to see any and all open tcp ports and connections
once paticular one caught my eye.
the one that caught my eye was the MS-SQL-S application, which was scrolling the log several thousand times a minute
here is a small snippet of the log:
System Process]:0 TCP localhost.secureserver.net:ms-sql-s n811p030.adsl.highway.telekom.at:2391 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s n811p030.adsl.highway.telekom.at:3468 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s n811p030.adsl.highway.telekom.at:3078 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s n811p030.adsl.highway.telekom.at:1918 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s n811p030.adsl.highway.telekom.at:1659 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s n811p030.adsl.highway.telekom.at:2814 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s n811p030.adsl.highway.telekom.at:2159 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:15221 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:25460 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:45944 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:41852 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:37764 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:27529 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:39824 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:31237 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:39831 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:41892 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:13222 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:48040 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:45996 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:39856 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:11190 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:43965 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:17346 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:23490 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:17354 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:9165 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:33741 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:37838 TIME_WAIT
Now i checked with the host of the server that i lease it from, and they said that the program was installed as part of the plesk package
heres my question, has the program been compromised ? if so, how can i fix this, if not, what in tarnation is it doing!
I checked a few of the ips (thoes were only 2 of several) and they come from random places, the ports also appear to be random as well, if anyone could shed some light on this it would be greatly appreciated, as of right now the MS-SQL-S service is halted and not running untill i can resolve this
Second question, is anything in the MS SQL service needed by plesk ? since its not part of the license key, and im using MySQL, im not even sure why it was installed.
I installed a program called tcpview from sysinternals, which allows me to see any and all open tcp ports and connections
once paticular one caught my eye.
the one that caught my eye was the MS-SQL-S application, which was scrolling the log several thousand times a minute
here is a small snippet of the log:
System Process]:0 TCP localhost.secureserver.net:ms-sql-s n811p030.adsl.highway.telekom.at:2391 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s n811p030.adsl.highway.telekom.at:3468 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s n811p030.adsl.highway.telekom.at:3078 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s n811p030.adsl.highway.telekom.at:1918 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s n811p030.adsl.highway.telekom.at:1659 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s n811p030.adsl.highway.telekom.at:2814 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s n811p030.adsl.highway.telekom.at:2159 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:15221 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:25460 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:45944 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:41852 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:37764 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:27529 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:39824 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:31237 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:39831 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:41892 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:13222 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:48040 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:45996 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:39856 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:11190 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:43965 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:17346 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:23490 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:17354 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:9165 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:33741 TIME_WAIT
[System Process]:0 TCP localhost.secureserver.net:ms-sql-s 69.13.40.146:37838 TIME_WAIT
Now i checked with the host of the server that i lease it from, and they said that the program was installed as part of the plesk package
heres my question, has the program been compromised ? if so, how can i fix this, if not, what in tarnation is it doing!
I checked a few of the ips (thoes were only 2 of several) and they come from random places, the ports also appear to be random as well, if anyone could shed some light on this it would be greatly appreciated, as of right now the MS-SQL-S service is halted and not running untill i can resolve this
Second question, is anything in the MS SQL service needed by plesk ? since its not part of the license key, and im using MySQL, im not even sure why it was installed.