LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 06-14-2010, 11:07 AM   #1
saharabear
LQ Newbie
 
Registered: Jul 2006
Location: Jinan, China
Distribution: Slackware, Slackiss
Posts: 21

Rep: Reputation: 0
What should I do when I find somebody changed my root password?


Hi, all:

I have a server, running on Slackware 13.1, has openssh&openssl update to current.

Today I find I can not access my root account, password is not correct, I believe somebody break my security rules, nobody has account on this machine, I have LAMP running on it.

What should I do at the moment? I have cut the network down, I think I can mount disk, clear root password, but what should I do next? How to find and clear the Cracker?

Thanks!
 
Old 06-14-2010, 11:12 AM   #2
amani
Senior Member
 
Registered: Jul 2006
Location: Kolkata, India
Distribution: Debian 64-bit GNU/Linux, Kubuntu64, Fedora QA, Slackware,
Posts: 2,766

Rep: Reputation: Disabled
If a system is compromised, then the right thing would be to recover data and if necessary do forensics with a forensic distro.
The system should be reinstalled after that
 
Old 06-14-2010, 11:21 AM   #3
ponce
LQ Guru
 
Registered: Aug 2004
Location: Pisa, Italy
Distribution: Slackware
Posts: 7,097

Rep: Reputation: 4174Reputation: 4174Reputation: 4174Reputation: 4174Reputation: 4174Reputation: 4174Reputation: 4174Reputation: 4174Reputation: 4174Reputation: 4174Reputation: 4174
just a few hints (these matters cannot be dissected on every aspect in forum posts, I think, there is people working on them for years and tons of docs to read):

first, be sure you haven't simply forgotten your root password: I manage a lot of hosts and (I know it's a stupid mistake but) it happens to me once in a while.

then, if it's really compromised, nothing will resume a clear situation as a reinstall.

but, if I were you, I would have a look at the things you're running on your lamp server and the lamp setup too (if you have changed something from the defaults) to avoid a comeback of the crackers: if they broke in they most probably have done it by some bugged webapp (but they have to be really bleeding edge, as the lamp software coming with slack 13.1 is up-to-date).

Last edited by ponce; 06-14-2010 at 11:28 AM.
 
Old 06-14-2010, 11:44 AM   #4
saharabear
LQ Newbie
 
Registered: Jul 2006
Location: Jinan, China
Distribution: Slackware, Slackiss
Posts: 21

Original Poster
Rep: Reputation: 0
Thanks for all your reply, I am trying to find what happened now, I do not know how they are in. I need to find what happened, otherwise, after I reinstall it, I can not believe it's safe again.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
root password changed lemon09 Linux - Newbie 8 08-18-2009 04:50 AM
My root password has changed?!!! defa0009 Linux - Security 35 05-18-2005 04:49 PM
system changed my root-password supersucker Linux - Software 2 01-16-2005 01:12 PM
Help Root password changed!!! UmneyDurak Fedora 4 09-28-2004 01:47 PM
someone changed my root password. what do i do? budds Linux - Security 4 09-12-2004 12:09 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 07:45 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration