VPS Hacked!! Please help

Discussion in 'Security' started by trustjon, Nov 28, 2010.

  1. #1
    Hello,


    I got this email today:

    IMPORTANT: Do not ignore this email.
    This message is to inform you that the account user has user id 0 (root privs). This could mean that your system was compromised (OwN3D). To be safe you should verify that your system has not been compromised.

    Can any one help??
     
    trustjon, Nov 28, 2010 IP
  2. ddmd

    ddmd Peon

    Messages:
    60
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #2
    I would suggest installing the open source ossec in there: http://www.ossec.net . It is very good at detecting rootkits and attacks to servers..

    thanks,

    --
    David Dede, http://sucuri.net
     
    ddmd, Nov 29, 2010 IP
  3. khan0072

    khan0072 Member

    Messages:
    38
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    41
    #3
    also install Mod_security it will helpful.
     
    khan0072, Nov 30, 2010 IP
  4. Chubby

    Chubby Peon

    Messages:
    3
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #4
    Linux or windows vps? Theirs a big difference.
     
    Chubby, Dec 4, 2010 IP
  5. davidove

    davidove Peon

    Messages:
    12
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #5
    This is a fake message you got in order to get you hacked email account. Don't follow and discard it. Mind your email password security, change it often and make it strong . Care also password recovery details so you can regain hacked yahoo email very quickly. Hack email account those days is very common so care your privacy email account. Mrerry christmas - cheers.
     
    Last edited: Dec 4, 2010
    davidove, Dec 4, 2010 IP
  6. blackvps

    blackvps Peon

    Messages:
    29
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Indeed, ignore it and if you want you can ask your host if they indeed did send it.
     
    blackvps, Dec 6, 2010 IP