Securing your root server

Skip to main content
Du bist hier:
Drucken

Securing your root server

A root server belongs entirely to you. That also means you are responsible for the security of the operating system. The most common reason Windows root servers get hacked is remote access (RDP) with a weak or even empty password. A few simple rules protect you reliably.

The most important rules

  • Never use an empty or simple password for an account with administrator rights, not even temporarily during setup.
  • Delete or disable accounts you no longer need, especially test and helper accounts with administrator rights.
  • Use your own administrator account and disable the default «Administrator» account if possible. It is the first target of automated attacks.
  • Keep Windows Update and antivirus enabled and check regularly that both are still running.
  • Restrict remote access: if possible, allow RDP in the Windows firewall only from known IP addresses. Access from outside Western Europe is blocked by default with us, see Unlock foreign access. Turn such an unlock off again as soon as you no longer need it.
  • Do not use «cleaner» tools for the system and registry. They modify system files and services and can make the server unstable.

How do you recognise an attack?

  • The server is suddenly very slow or the desktop stops responding.
  • CPU load stays high although you are not running anything demanding.
  • Antivirus or Windows Update has suddenly been switched off.
  • There are user accounts or programs you do not recognise.

What to do if your server is affected

Open a ticket right away and change the passwords of all users on the server, including passwords stored on it (for example for email accounts). Important: once an attacker had administrator rights, it can no longer be reliably proven that the server is completely clean again, even after removing the malware found. In that case we recommend a clean rebuild of the server with a controlled transfer of your data. We will support you with this.

Related Post