In seaching for the info listed on the webpage it seems this has happened to many people but could not find much info on the hack itself and how this particullar hacker gains access.
I have researched this and it is really a windows 2000 issue that is not very fixable at all due to the way asp.net runs on windows 2000, another reason for us to get win5 upgraded ASAP.
However it was all due to an insecure phpbb2 forum that has 0 updates since 2004. Then he uploaded as asp.net app, and about 15 users with asp.net user having full permissions(which is not used anymore and would prevent this if less than full permissions, it likley happened literally years ago). The users with asp.net having full permissions had some sites defaced. We will be getting Win5 over to Windows 2003 very soon, and the urgency of it is being accelerated after this, the 2000 server process model is really not good.
deepscan, it was NOT done via FTP, it was done with an asp.net script for only users having their whole user with asp.net permissions set to full level(should be set at domain level) the permissions have likely been like this for years now, and the way windows 2000 works asp.net does not have process/user isolation for asp.net, so with incorrect permissions the defacer was able to use a script to edit files outside the originally hacked users folder for about 15 users having “full” permissions at the inherited level from the user directory. Asi mentioned, it was about 15 users in all.
deepscan, if you are on win5 that reply was valid, if your domain is on win21, that is a very localized issue and only one user that is repeatedly having their site defaced.
Feel free to PM me, but I know for a fact win5 situation was not FTP, and win21 was not for all the files replaced, not sure on the actual source yet, I have seen it many times however, it is 99.99999% of the time due to a file upload tool allowing all uploads instead of just images, etc