Navigation X
ALERT
Click here to register with a few steps and explore all our cool stuff we have to offer!



 373

RDP got hacked, how do I catch the hacker?

by thepro6969 - 01 April, 2021 - 09:30 PM
This post is by a banned member (thepro6969) - Unhide
93
Posts
6
Threads
4 Years of service
#1
somehow, someone reset (i think?) my server. 

nothing was left except this user is logged in with microsoft account : [email protected]
and this name : 
[Image: fAgEBze.png]

what else to do now? is this even worth investigating? 
also, how do i recover data for now? 

completely panicked. help :(
This post is by a banned member (TimHortons) - Unhide
1.160
Posts
367
Threads
4 Years of service
#2
who owns the rdp?
 
This post is by a banned member (MoneyUp) - Unhide
MoneyUp  
Registered
130
Posts
71
Threads
3 Years of service
#3
(01 April, 2021 - 09:30 PM)thepro6969 Wrote: Show More
somehow, someone reset (i think?) my server. 

nothing was left except this user is logged in with microsoft account : [email protected]
and this name : 
[Image: fAgEBze.png]

what else to do now? is this even worth investigating? 
also, how do i recover data for now? 

completely panicked. help :(

Press F to pay respects.
Did you download any suspicious software?
 ───────⚪───────────────────────────────── ⠀ ▐▐ ⠀►▏ ⠀⠀──○─ ₁:₂₅ / ₃:₅₀
Instant Walmart Refunds And Walmart + Amazon Triple Dips
[Image: fIm0tN5.gif]


I love people who +rep me!
I
love people who like my posts!
I normally
+rep users that I like!


Discord: MoneyUp#9466 | Telegram: @MoneyUpCTO
This post is by a banned member (thepro6969) - Unhide
93
Posts
6
Threads
4 Years of service
#4
(This post was last modified: 01 April, 2021 - 09:41 PM by thepro6969.)
(01 April, 2021 - 09:31 PM)TimHortons Wrote: Show More
who owns the rdp?

me. it's a QEMU inside a linux server. I have a little complicated server setup, yeah. 
but i swear this server is mine, really.

(01 April, 2021 - 09:31 PM)MoneyUp Wrote: Show More
(01 April, 2021 - 09:30 PM)thepro6969 Wrote: Show More
somehow, someone reset (i think?) my server. 

nothing was left except this user is logged in with microsoft account : [email protected]
and this name : 
[Image: fAgEBze.png]

what else to do now? is this even worth investigating? 
also, how do i recover data for now? 

completely panicked. help :(

Press F to pay respects.
Did you download any suspicious software?

I don't think so. The only thing i can imagine is someone know one of admin password. 
but nobody is in russia, so i don't think anyone doing malicious there. 

the hacker is idiot enough to reset the windows and destroy the RDP access lol

Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
or
Sign in
Already have an account? Sign in here.


Forum Jump:


Users browsing this thread: 1 Guest(s)