LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-14-2006, 12:44 PM   #1
guysoft
Member
 
Registered: Jun 2004
Location: israel
Distribution: mandrake, MEPIS and menny live-cds
Posts: 71

Rep: Reputation: 16
I was HACKED BY ALEKS - HELP!!!


hello,
i run the server gnet.homelinux.com, on debian unstable.

this hacker replaced files in an installation of dokuwiki.

as i was using ssh to check the damage i got:
Code:
ssh_exchange_identification: Connection closed by remote host
i immediately switched off the PC.

when i switch it on what to look for? what might show that he sshed?

what to do in this situation?
 
Old 03-14-2006, 01:19 PM   #2
gilead
Senior Member
 
Registered: Dec 2005
Location: Brisbane, Australia
Distribution: Slackware64 14.0
Posts: 4,141

Rep: Reputation: 168Reputation: 168
I'd suggest getting that box off the network and then from another box go through the information on forensics and recovery at http://www.linuxquestions.org/questi...600#post222600. There's a lot of information there and it should help you determine what has happened.
 
Old 03-14-2006, 01:28 PM   #3
guysoft
Member
 
Registered: Jun 2004
Location: israel
Distribution: mandrake, MEPIS and menny live-cds
Posts: 71

Original Poster
Rep: Reputation: 16
do you have something more specific? that list is full of sites, i don't know where to start.
 
Old 03-14-2006, 01:49 PM   #4
gilead
Senior Member
 
Registered: Dec 2005
Location: Brisbane, Australia
Distribution: Slackware64 14.0
Posts: 4,141

Rep: Reputation: 168Reputation: 168
To start with, you'll need to get the system off the network, back it up and check your log files to see if anything has been logged that points to what they've done. Your Apache logs and several of the files in /var/log (secure, messages, syslog) may have information. But if it was someone who knew what they were doing and gained sufficient access, they'll have tried to hide what they did.

It's worth going through the links on that page because going through the process may show that you weren't cracked at all. Or, if you were, you'll have a wide range of tools you can apply to find the problems. The first link in the forensics section (http://www.cert.org/tech_tips/root_compromise.html) goes through some steps to determine whether you've been cracked. I'd sugest you have a look in the "C. Analyze the intrusion" section and ask more questions here about what you find...
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Am I being Hacked ? rizhun Linux - Security 4 09-07-2005 08:08 AM
Could have been hacked! Help! Charles Daniel Linux - Security 28 08-03-2005 06:17 AM
Hacked!! vharishankar General 16 02-07-2005 08:12 AM
I got hacked hannes5020 Red Hat 4 05-07-2004 12:13 PM
i think i've been hacked! safil Linux - Security 7 11-02-2003 10:16 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:56 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration