dbTalk Databases Forums  

Malicious PPStreamSetup.exe hack

comp.databases.paradox comp.databases.paradox


Discuss Malicious PPStreamSetup.exe hack in the comp.databases.paradox forum.



Reply
 
Thread Tools Display Modes
  #1  
Old   
Jim Moseley
 
Posts: n/a

Default Malicious PPStreamSetup.exe hack - 11-21-2008 , 04:14 PM







OK, here's a first. One of my clients was using my application when a Windows
window popped up saying 'Copying...'. They cancelled this, since they didn't
start it. A minute later, the app stopped working.

Someone had hacked into their server & installed ppstreamsetup.exe in their
shared folder, and also stolen all of their forms, reports, and libraries
- but no tables! Luckily we back up their data to our servers nightly so
they didn't lose anything.

I've changed their share folder security to remove 'Everyone', so hopefully
that keeps them out. They've got a network tech coming in tomorrow to make
sure.

I'm still not sure if they ran the setup or just installed it for later.
Either way, I deleted it.

Just an FYI.
Jim Moseley

Reply With Quote
  #2  
Old   
Tony McGuire
 
Posts: n/a

Default Re: Malicious PPStreamSetup.exe hack - 11-21-2008 , 05:53 PM






Jim Moseley wrote:
Quote:
OK, here's a first. One of my clients was using my application when a Windows
window popped up saying 'Copying...'. They cancelled this, since they didn't
start it. A minute later, the app stopped working.

Someone had hacked into their server & installed ppstreamsetup.exe in their
shared folder, and also stolen all of their forms, reports, and libraries
- but no tables! Luckily we back up their data to our servers nightly so
they didn't lose anything.

I've changed their share folder security to remove 'Everyone', so hopefully
that keeps them out. They've got a network tech coming in tomorrow to make
sure.

I'm still not sure if they ran the setup or just installed it for later.
Either way, I deleted it.

Just an FYI.
Jim Moseley
If they have their system open, gotta ask...do they have any antivirus
on their systems? How about anti-malware?

Sounds really suspicious that someone would take forms & such (delivered
only?) and not touch the tables. They'd have to know what was going on
to selectively take (or erase?) and leave the tables alone (although
they could copy without deleting so you never know where their data now
resides.

Good luck.

---------------
Tony McGuire


Reply With Quote
  #3  
Old   
Tony McGuire
 
Posts: n/a

Default Re: Malicious PPStreamSetup.exe hack - 11-21-2008 , 05:53 PM



Jim Moseley wrote:
Quote:
OK, here's a first. One of my clients was using my application when a Windows
window popped up saying 'Copying...'. They cancelled this, since they didn't
start it. A minute later, the app stopped working.

Someone had hacked into their server & installed ppstreamsetup.exe in their
shared folder, and also stolen all of their forms, reports, and libraries
- but no tables! Luckily we back up their data to our servers nightly so
they didn't lose anything.

I've changed their share folder security to remove 'Everyone', so hopefully
that keeps them out. They've got a network tech coming in tomorrow to make
sure.

I'm still not sure if they ran the setup or just installed it for later.
Either way, I deleted it.

Just an FYI.
Jim Moseley
If they have their system open, gotta ask...do they have any antivirus
on their systems? How about anti-malware?

Sounds really suspicious that someone would take forms & such (delivered
only?) and not touch the tables. They'd have to know what was going on
to selectively take (or erase?) and leave the tables alone (although
they could copy without deleting so you never know where their data now
resides.

Good luck.

---------------
Tony McGuire


Reply With Quote
  #4  
Old   
Tony McGuire
 
Posts: n/a

Default Re: Malicious PPStreamSetup.exe hack - 11-21-2008 , 05:53 PM



Jim Moseley wrote:
Quote:
OK, here's a first. One of my clients was using my application when a Windows
window popped up saying 'Copying...'. They cancelled this, since they didn't
start it. A minute later, the app stopped working.

Someone had hacked into their server & installed ppstreamsetup.exe in their
shared folder, and also stolen all of their forms, reports, and libraries
- but no tables! Luckily we back up their data to our servers nightly so
they didn't lose anything.

I've changed their share folder security to remove 'Everyone', so hopefully
that keeps them out. They've got a network tech coming in tomorrow to make
sure.

I'm still not sure if they ran the setup or just installed it for later.
Either way, I deleted it.

Just an FYI.
Jim Moseley
If they have their system open, gotta ask...do they have any antivirus
on their systems? How about anti-malware?

Sounds really suspicious that someone would take forms & such (delivered
only?) and not touch the tables. They'd have to know what was going on
to selectively take (or erase?) and leave the tables alone (although
they could copy without deleting so you never know where their data now
resides.

Good luck.

---------------
Tony McGuire


Reply With Quote
  #5  
Old   
Tony McGuire
 
Posts: n/a

Default Re: Malicious PPStreamSetup.exe hack - 11-21-2008 , 05:53 PM



Jim Moseley wrote:
Quote:
OK, here's a first. One of my clients was using my application when a Windows
window popped up saying 'Copying...'. They cancelled this, since they didn't
start it. A minute later, the app stopped working.

Someone had hacked into their server & installed ppstreamsetup.exe in their
shared folder, and also stolen all of their forms, reports, and libraries
- but no tables! Luckily we back up their data to our servers nightly so
they didn't lose anything.

I've changed their share folder security to remove 'Everyone', so hopefully
that keeps them out. They've got a network tech coming in tomorrow to make
sure.

I'm still not sure if they ran the setup or just installed it for later.
Either way, I deleted it.

Just an FYI.
Jim Moseley
If they have their system open, gotta ask...do they have any antivirus
on their systems? How about anti-malware?

Sounds really suspicious that someone would take forms & such (delivered
only?) and not touch the tables. They'd have to know what was going on
to selectively take (or erase?) and leave the tables alone (although
they could copy without deleting so you never know where their data now
resides.

Good luck.

---------------
Tony McGuire


Reply With Quote
  #6  
Old   
Tony McGuire
 
Posts: n/a

Default Re: Malicious PPStreamSetup.exe hack - 11-21-2008 , 05:53 PM



Jim Moseley wrote:
Quote:
OK, here's a first. One of my clients was using my application when a Windows
window popped up saying 'Copying...'. They cancelled this, since they didn't
start it. A minute later, the app stopped working.

Someone had hacked into their server & installed ppstreamsetup.exe in their
shared folder, and also stolen all of their forms, reports, and libraries
- but no tables! Luckily we back up their data to our servers nightly so
they didn't lose anything.

I've changed their share folder security to remove 'Everyone', so hopefully
that keeps them out. They've got a network tech coming in tomorrow to make
sure.

I'm still not sure if they ran the setup or just installed it for later.
Either way, I deleted it.

Just an FYI.
Jim Moseley
If they have their system open, gotta ask...do they have any antivirus
on their systems? How about anti-malware?

Sounds really suspicious that someone would take forms & such (delivered
only?) and not touch the tables. They'd have to know what was going on
to selectively take (or erase?) and leave the tables alone (although
they could copy without deleting so you never know where their data now
resides.

Good luck.

---------------
Tony McGuire


Reply With Quote
  #7  
Old   
Tony McGuire
 
Posts: n/a

Default Re: Malicious PPStreamSetup.exe hack - 11-21-2008 , 05:53 PM



Jim Moseley wrote:
Quote:
OK, here's a first. One of my clients was using my application when a Windows
window popped up saying 'Copying...'. They cancelled this, since they didn't
start it. A minute later, the app stopped working.

Someone had hacked into their server & installed ppstreamsetup.exe in their
shared folder, and also stolen all of their forms, reports, and libraries
- but no tables! Luckily we back up their data to our servers nightly so
they didn't lose anything.

I've changed their share folder security to remove 'Everyone', so hopefully
that keeps them out. They've got a network tech coming in tomorrow to make
sure.

I'm still not sure if they ran the setup or just installed it for later.
Either way, I deleted it.

Just an FYI.
Jim Moseley
If they have their system open, gotta ask...do they have any antivirus
on their systems? How about anti-malware?

Sounds really suspicious that someone would take forms & such (delivered
only?) and not touch the tables. They'd have to know what was going on
to selectively take (or erase?) and leave the tables alone (although
they could copy without deleting so you never know where their data now
resides.

Good luck.

---------------
Tony McGuire


Reply With Quote
  #8  
Old   
Tony McGuire
 
Posts: n/a

Default Re: Malicious PPStreamSetup.exe hack - 11-21-2008 , 05:53 PM



Jim Moseley wrote:
Quote:
OK, here's a first. One of my clients was using my application when a Windows
window popped up saying 'Copying...'. They cancelled this, since they didn't
start it. A minute later, the app stopped working.

Someone had hacked into their server & installed ppstreamsetup.exe in their
shared folder, and also stolen all of their forms, reports, and libraries
- but no tables! Luckily we back up their data to our servers nightly so
they didn't lose anything.

I've changed their share folder security to remove 'Everyone', so hopefully
that keeps them out. They've got a network tech coming in tomorrow to make
sure.

I'm still not sure if they ran the setup or just installed it for later.
Either way, I deleted it.

Just an FYI.
Jim Moseley
If they have their system open, gotta ask...do they have any antivirus
on their systems? How about anti-malware?

Sounds really suspicious that someone would take forms & such (delivered
only?) and not touch the tables. They'd have to know what was going on
to selectively take (or erase?) and leave the tables alone (although
they could copy without deleting so you never know where their data now
resides.

Good luck.

---------------
Tony McGuire


Reply With Quote
Reply




Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Powered by vBulletin Version 3.5.3
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.