I have two machines within my network with similar configurations..
Windows 2000 Server SP4 with latest updates from Microsoft Updates. They are
both behind dedicated (which means each server has its own Firewall) Watchguard
Firebox III. Only 3389 (terminal services) web ftp, and the like are open.
Services such as 445, 135-139 and the common virii spreading/Trojan spreading
ports are not open on these servers.
Tonight on two separate occasions I have had to reboot these servers
after having them both run flawlessly for months without having to reboot them
except for update purposes. Now, having to reboot one of them, I could see.
Having to reboot two of them.. that's a little strange.. Anyone hear of
anything new going around? I haven't heard of anything on regular sec focus
yet. These servers aren't connected to a DC or anything. No need to reply if
you haven't noticed anything unusual.
Thanks,
-Drew