Jump to content

Recommended Posts

Posted

A few days ago I configured a remote apps server, it works brilliantly internally and externally. It's very early days and I intended to use Microsoft's grace period while SLT had a bit of a play before we agreed to buy licenses and an SSL certificate. But I was amazed to see how some idiot with too much time found their way in to my server and leave me a message offering the chance to buy bitcoins for them, or something like that. B*rst*ds!

 

So my question is, what is the best way to secure this server, is an SSL certificate the only and best way, along with secure credentials, or can I do more. Right now I'm a little nervous I can easily spin up another VM but how long will it last and how much more damage can they do?

 

Thanks

Posted

I mean there shouldn't be a way an external person can connect at all unless you either changed to allow anonymous settings etc, or you have an account with a very simple password :p

 

If you look in the logs on the server what account was used to login to it? I'm assuming you're using the standard webform login?

 

Steve

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...