Someone recently got into my server

Discussion in 'Site & Server Administration' started by mypoint, Mar 7, 2009.

  1. #1
    Hi someone recently got into my server and changed the root password. However i was able to change it back.

    I was just wondering how can i check to see if any damage was caused? And im running cpanel on my fedora server how can i make sure that everything is setup right so users cant access files and folder they are not suppose to be in or places where they can easily upload bots to.

    Let me know thanks!
     
    mypoint, Mar 7, 2009 IP
  2. Pathan

    Pathan Well-Known Member

    Messages:
    2,196
    Likes Received:
    218
    Best Answers:
    0
    Trophy Points:
    165
    #2
    you may check the log file, it will help you to see what the attacker have done. or ask some expert to investigate this issue completely.
     
    Pathan, Mar 7, 2009 IP
  3. mypoint

    mypoint Well-Known Member

    Messages:
    985
    Likes Received:
    6
    Best Answers:
    0
    Trophy Points:
    110
    #3
    yea i am going to hire experts. Where can i find the log file though?
     
    mypoint, Mar 8, 2009 IP
  4. Camay123

    Camay123 Well-Known Member

    Messages:
    3,423
    Likes Received:
    86
    Best Answers:
    0
    Trophy Points:
    160
    #4
    /var/log ?
     
    Camay123, Mar 8, 2009 IP
  5. mypoint

    mypoint Well-Known Member

    Messages:
    985
    Likes Received:
    6
    Best Answers:
    0
    Trophy Points:
    110
    #5
    yea i am in var log but dont know exactly what file to look in.

    thanks!
     
    mypoint, Mar 8, 2009 IP
  6. SSANZ

    SSANZ Peon

    Messages:
    861
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Honestly, why even say this? Your making no sense.

    • Logs will be cleaned/patched upon attackers rootkit initiation
    • Rootkit / backdoor installed to gain access at a later point in time
    • Loggers - log passwds, keys & activity
    • defacement/php shells - later access or deface

    You need a server administrator to clean your server system, a full reinstall of OS is highly recommended, take backups of your data ASAP.

    Finding the original breach of security will be a priority for you, as you dont need another breach happening.
     
    SSANZ, Mar 9, 2009 IP