Server Compromised??? Missing 100Gb!!!
Results 1 to 9 of 9

Thread: Server Compromised??? Missing 100Gb!!!

  1. #1
    Registered User daveah's Avatar
    Join Date
    Nov 2004
    Posts
    4

    Exclamation Server Compromised??? Missing 100Gb!!!

    Dell Server
    Xeon 3.06GHz 1Gb Ram
    2x PERC LD PERCRAID SCSI Drives

    Disk 0 Basic NTFS 33.86 Gb
    3x Partitions
    31Mb (EISA Configuration)
    15.01Gb C:
    18.82Gb D:

    Disk 1 Basic NTFS 169.33 Gb
    169.33Gb E:

    The problem is the E: drive, it has 2 visible and 2 hidden directories:-
    E:\Microsoft SQL Server\ (Size On Disk 328,167,424 bytes)

    E:\RECYCLER\ (Size On Disk 8,192 bytes)
    E:\System Volume Information (Size On Disk 0 bytes)
    E:\WUTemp (Size On Disk 0 bytes)

    All of which add up to 328,175,616 bytes.

    However when I look at the properties for the drive I get this:

    Used space : 108,066,578,432 bytes 100Gb
    Free space : 73,753,202,688 bytes 68.6Gb
    Capacity : 181,819,781,120 bytes 169Gb

    WHEREs THAT 100Gb GONE TO!!!!??????

    I believe it may have been compromised as it was accidently left outside the firewall for a time and I understand the network logs showing it having some 10Mb/sec traffic with protocols indicating it may have been streaming video/music/etc... (I don't personnally have access to these logs btw).

    However, the fact remains theres 100Gb disapeared and I cant see it. Is there someway for me to see this data and verifywhat it is AND where it is and possibly if theres anymore hidden on the other partitions and, god forbid, any other server.

    So, pleasepleasepleasepleasepleasepleaseplease heeeelllllllpp Thanking you in advance

    Dave
    Last edited by daveah; November 5th, 2004 at 04:13 AM.

  2. #2
    Laptops/Notebooks/PDA Mod 3fingersalute's Avatar
    Join Date
    Jun 2001
    Location
    PA
    Posts
    3,880
    Who has access to the logs? Are you the administrator of the server?

    Are you 100% certain that there are no other directories on the root of the E: drive? What about any files on the root of E:? Is view hidden files and folders turned on under the view menu? Also, try unchecking "Hide protected operating system files" from the view menu as well, then open E:, select all, right-click and then properties, what does it show for total size used??

  3. #3
    Registered User gazzak's Avatar
    Join Date
    Jun 2002
    Location
    London, England
    Posts
    3,595
    Have you looked into disk management and see what information that gives you about the drive? Does the system recognise the actual disk size? Is some of it not partitioned?
    There's no panic like the panic you momentarily feel when you've got
    your hand or head stuck in something

  4. #4
    Registered User daveah's Avatar
    Join Date
    Nov 2004
    Posts
    4
    Quote Originally Posted by 3fingersalute
    Who has access to the logs? Are you the administrator of the server?

    Are you 100% certain that there are no other directories on the root of the E: drive? What about any files on the root of E:? Is view hidden files and folders turned on under the view menu? Also, try unchecking "Hide protected operating system files" from the view menu as well, then open E:, select all, right-click and then properties, what does it show for total size used??
    Yep, I'm the admin.

    I've set the Folder Options to show system and hidden files/folders, and no, theres no more files/folders.

    As mentioned previously, the drive properties are:-
    Used space : 108,066,578,432 bytes 100Gb
    Free space : 73,753,202,688 bytes 68.6Gb
    Capacity : 181,819,781,120 bytes 169Gb

  5. #5
    Registered User daveah's Avatar
    Join Date
    Nov 2004
    Posts
    4
    Quote Originally Posted by gazzak
    Have you looked into disk management and see what information that gives you about the drive? Does the system recognise the actual disk size? Is some of it not partitioned?
    Yep, the system does see the full, correct size of the disk in Disk Management
    Capacity: 169.33
    Free space: 68.69Gb

  6. #6
    Registered User GreenGrime's Avatar
    Join Date
    Oct 2004
    Location
    Right here, right now
    Posts
    181
    Use a boot CD if you can to take a complete look at that disk outside of Windows.

    Ultimate Boot CD has some tools to help you do that.

  7. #7
    Registered User gizmo1_1's Avatar
    Join Date
    Aug 1999
    Location
    root@localhost>
    Posts
    350
    Quote Originally Posted by daveah
    The problem is the E: drive, it has 2 visible and 2 hidden directories:-
    E:\Microsoft SQL Server\MSSQL\Data (Size On Disk 328,167,424 bytes)
    You are indicating the size of the Subdirectory data in this statement. Have you checked the size of E:\Microsoft SQL Server itself
    It is a miracle that curiosity survives formal education. -- Albert Einstein
    It said 'Insert disk #3', but only two will fit. -- The average customer.
    "There is no need for any individual to have a computer in their home." – Ken Olson, President of Digital Equipment Corp., 1977 …….

    [email protected]

  8. #8
    Registered User daveah's Avatar
    Join Date
    Nov 2004
    Posts
    4
    Quote Originally Posted by gizmo1_1
    You are indicating the size of the Subdirectory data in this statement. Have you checked the size of E:\Microsoft SQL Server itself
    Sorry, my mistake, was intending to show the tree but thought better of it mid-type.

    That figure is for the top level directory.
    E:\Microsoft SQL Server\ (Size On Disk 328,167,424 bytes)

    Now amended

  9. #9
    Senior Member Garak's Avatar
    Join Date
    Jun 2001
    Location
    Hebburn, Tyne & Wear, North East England
    Posts
    2,448
    lost and trunacted files would be a cause. how about a chkdsk?
    All sorts of wonderful things in life.

Similar Threads

  1. [RESOLVED] 70-240: LETS DO THIS!!
    By 70-240 in forum Certification
    Replies: 14
    Last Post: February 20th, 2012, 03:35 AM
  2. Replies: 22
    Last Post: May 28th, 2004, 07:49 PM
  3. missing IPC$ and admin$ in windows 200 server
    By karubin in forum Windows NT/2000
    Replies: 1
    Last Post: May 27th, 2004, 07:30 AM
  4. DHCP redundancy
    By Ya_know in forum Tech-To-Tech
    Replies: 8
    Last Post: February 14th, 2003, 02:28 AM
  5. [RESOLVED] W2K SP2??
    By Bjorn in forum Windows NT/2000
    Replies: 3
    Last Post: February 17th, 2001, 12:58 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •