Linux - SecurityThis forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.
Notices
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
I am a linux newbie so sorry if these are standard *nix questions.
I have a public facing linux server and I notice there is a /home/backdoor directory alongside /home directories for other users that have logged in. It sounds dodgy to me. Is there any way I can find out whether there are login details for a user backdoor and whether it has been used?
What time/date was the backdoor directory created? Is there anything listed from last backdoor? You'll probably get more responses on this thread if its in the security forum. I'll request its moved for you.
Ooohhh... That really doesn't look good. Read over those links, take your system offline if you care about it...
It appears, to me, to have a UID of 0. This is root's uid. If a user has a uid of 0 the user is "seen" by your system as root himself (which is bad).
If you don't have a root password, create one. If you have one, change it. Read those links above, and uh, good luck
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.