Something is wrong with my server

Discussion in 'Site & Server Administration' started by phantomddl, May 13, 2007.

  1. #1
    until 2 hours ago everythng was fine. now i cant connect ftp, ssh etc.. but sites open in browser(main page slow, other pages fast).
    i have rebooted server 3 times but everything is same. i also found out an iframe code in one of my sites(i havent added)
    i think someone crashed my server. what do i have to do? do u suggest any antiviruses?
    p.s. Linux Server
     
    phantomddl, May 13, 2007 IP
  2. agnivo007

    agnivo007 Peon

    Messages:
    4,290
    Likes Received:
    289
    Best Answers:
    0
    Trophy Points:
    0
    #2
    Maybe someone utilised vulnerabilities in your script or server software.

    I'd suggest you to contact your server provider, make backups, rebuild server with latest packages and restore the account backups.
     
    agnivo007, May 13, 2007 IP
  3. randomIntellections

    randomIntellections Well-Known Member

    Messages:
    985
    Likes Received:
    13
    Best Answers:
    0
    Trophy Points:
    180
    #3
    nothing can be done until ssh is backup . once its back you can have a look at the access logs , http logs , raw access logs . processes running , run rootkit checks , Anti virus are not required , check for script updates , patches to os , server software , harden server .
     
    randomIntellections, May 14, 2007 IP
  4. phantomddl

    phantomddl Well-Known Member

    Messages:
    2,856
    Likes Received:
    30
    Best Answers:
    0
    Trophy Points:
    160
    Articles:
    15
    #4
    eh.. i checked ssh logs, there was a brute force sincs 4april and he succeed yesterday. anyways, my server is messed up. can anyone help me with it? my sites not opening anymore, even tho apache is running. i lost 50k unique hits yesterday..
    i will pay if you dont want too much money..
     
    phantomddl, May 14, 2007 IP
  5. inworx

    inworx Peon

    Messages:
    4,860
    Likes Received:
    201
    Best Answers:
    0
    Trophy Points:
    0
    #5
    I can help.

    Please PM me. I will do i9t for free if it isnt complicated. If it is, I would charge a small fee:D
     
    inworx, May 14, 2007 IP
  6. chilli_source

    chilli_source Active Member

    Messages:
    58
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    61
    #6
    imo your server needs to be either reinstalled or get a new server, as
    the hacker could've planted malicious scripts anywhere on the box, you could end up in the situation in you're in now at any time.

    once a server is comprimised you really need to start fresh, then lock everything down so it's secure and restore from your latest backup.
     
    chilli_source, May 14, 2007 IP
  7. phantomddl

    phantomddl Well-Known Member

    Messages:
    2,856
    Likes Received:
    30
    Best Answers:
    0
    Trophy Points:
    160
    Articles:
    15
    #7
    thanx for the suggestions. i have almost fixed everythng. just some lil things left
     
    phantomddl, May 14, 2007 IP
  8. randomIntellections

    randomIntellections Well-Known Member

    Messages:
    985
    Likes Received:
    13
    Best Answers:
    0
    Trophy Points:
    180
    #8
    PM if you need anything , though i dont work for free.
     
    randomIntellections, May 14, 2007 IP