Been Hacked! May I get control of my Root user again?
Linux - SecurityThis forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.
Notices
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
Been Hacked! May I get control of my Root user again?
Hi!
It looks like I have been hacked last week. I can't log with neither root or other users with sudo rights. I have physicall access to the server and would like to know if there is a possibility to get control over my server (FC 6) again with the help of any tool like a rescue live cd that would allow me to set up a new root's password?
thanks for any help.
P.S. I would like to get in the machine again in order to get a few datas and have a look at the log files. Then I plan to reinstall the whole stuff again.
as long as you don't ever plan to *use* the server to any extent again then that's fine... at the bootloader screen go into edit mode, e in grub, not sure what it is in lilo, and just add a "1" into the kernel options and then boot. this will automatically dump you in as root letting you change whatever you want to...
To follow up, once you are able to get access to the system, take a look at the links in the security references thread at the top of the forum. Take a look at the section "Compromise, breach of security, detection", In particular the links to CERT's Intruder Detection Checklist and "Steps for Recovering from a UNIX or NT System Compromise" will likely be useful in diagnosing the source of the compromise. Remember that if you are truly compromised, then a full reinstall from trusted media is the *only* way you can be sure that the system is secure.
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.