LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-07-2013, 12:18 AM   #1
prashant.jadhav
LQ Newbie
 
Registered: Jul 2013
Posts: 2

Rep: Reputation: Disabled

Hello,

One of my dedicated server's root access has been compromised due to which i could not SSH the server. How should i troubleshoot this issue ? Kindly suggest.
Could you please suggest me probable troubleshooting steps which i could follow on server to resolve this issue ?

Regards,
Linux Admin

Last edited by unSpawn; 10-07-2013 at 01:31 AM. Reason: //Merge impatient reply
 
Old 10-07-2013, 01:12 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by prashant.jadhav View Post
One of my dedicated server's root access has been compromised due to which i could not SSH the server.
Not being able to SSH into a server can have many reasons ranging from fat fingering auth to wrong (re)configuration or access restrictions to the server being overloaded or service or server or network unavailability. Check network and service availability and if the machine is remotely monitored check that and its log / alerts first. Next check if the machine can be reached over a remote console (DRAC, iLO or IPMI) or web-based management panel to restart the SSH service or do first recon using the CERT Intruder Detection Checklist.

*If you however tried to convey you found out the machine was compromised earlier or in a different way then you should have been much, much clearer about it and follow the same checklist and give us more nfo.

For the sake of efficiency I expect your next reply to be complete and verbose, listing the steps you took and relevant stdout / stderr output etc, etc.
 
Old 10-07-2013, 02:51 AM   #3
CodeFreaker
LQ Newbie
 
Registered: Feb 2010
Posts: 27

Rep: Reputation: 12
Quote:
Originally Posted by prashant.jadhav View Post
Hello,

One of my dedicated server's root access has been compromised due to which i could not SSH the server. How should i troubleshoot this issue ? Kindly suggest.
Could you please suggest me probable troubleshooting steps which i could follow on server to resolve this issue ?

Regards,
Linux Admin
Do you can ssh using any other user?if you can then there is no problem with SSH.
1.check ssh config where /etc/ssh/sshd_and configuration PermitRootLogin is no.If that is yes or commented then seems like your root password has been changed.Then go to run level 1 in boot time and reset the password.

Anyway you have to log terminal machine itself to do these all..
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Root Access of Server compromised prashant.jadhav Linux - Server 3 10-07-2013 04:53 AM
root access on my own server dimitris.hys Ubuntu 3 10-30-2012 09:01 AM
[SOLVED] Only allow root ssh access to the server replica88 Linux - Security 6 02-20-2010 08:36 AM
no access for root on X-server (local) Li... Debian 11 02-16-2004 06:01 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:22 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration