LinuxQuestions.org
Review your favorite Linux distribution.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 01-28-2005, 11:41 AM   #1
rkane
Member
 
Registered: May 2003
Location: Ohio
Distribution: Slackware
Posts: 47

Rep: Reputation: 15
Unhappy Reiserfs, hacker and bad blocks


First off, if this message should be in a different forum I'm sorry, Was a tossup between where I found other Reiser stuff, and the Security forum.

This morning, my linux box was down when I came to work. I got into it and looked at my log files and found nothing. But there was a new /home/chris directory, with no files in it. No command log or anything. I could not get to the webpages that I had setup, and while working with the box I got errors about bad sectors. I shut down the system and a reboot did not repair the reiserfs. I restarted again with a bootable CD and I cannot get reiserfsck to rebuild-tree, or fix-fixable. It reports there is a bad block. this may be a hardware issue. I'm not sure which version of reiserfsck I have, but I do have Slackware 9.0. I do not know how the hack came in, because the only ports that are open to the outside are 21(SSH), and 8080(HTTP). My password, though not foolproof is very well constructed against hacking and the root password is even stronger.

My first question is, is there a way that this person could have created bad blocks on my hard drive in and effort to keep me from finding him/her?
My second question is, How do I get reiserfs to recognize these bad blocks and allow me to mount the hard drive, or is there a way to have mount not check the disk when I'm mounting it?

I know some of my software is out of date, and maybe that is how they found a way in the system. I'm only a techie part of the time so I don't get all the updates done when they should be. I do have a backup of the mysql database, and of the home directory that was done 2 days ago. Yesterday's backup, and the one from the day before were both corrupt.

I am going to install Slackware 10.0 on a new hard drive in this computer, and hook up the old one as a slave so that i can try and run reiserfsprogs, and see if there is anything I can do to get at the information to track this hacker down. I will be using Ext3 now also, because there are soooo many more tools out here to help with it.

I will have to lock out port 21 now, because I'm paranoid now, and I'll have to setup the webpages on a random port instead of using a common port like 8080.
This is all done on our router, that was given us by our ISP.

Any help in with getting back into this hard drive, or recommendations to help figure out what happened would be greatly appreciated.

Thanks in advance,
Rkane
 
Old 01-28-2005, 02:25 PM   #2
BrianK
Senior Member
 
Registered: Mar 2002
Location: Los Angeles, CA
Distribution: Debian, Ubuntu
Posts: 1,334

Rep: Reputation: 51
Maybe it's a typo, but port 21 is ftp, not ssh - unless you've done something odd.

As far as reiser goes, did you get it to mount the filesystem at all? Did you mount as read only for the first check? Can you run a check at all (i.e., mount as ro and run reiserfsck --check /dev/hda)? is this your system drive or a separate, storage drive?

...Just trying to get a feel of where you're at in the process.

You probably know, but to run resierfsck --check, the drive must be mounted ro, but you run the check on the /dev entry for the drive. To run --rebuild-tree, it must be unmounted.
 
Old 01-28-2005, 02:58 PM   #3
rkane
Member
 
Registered: May 2003
Location: Ohio
Distribution: Slackware
Posts: 47

Original Poster
Rep: Reputation: 15
Sorry, typo on the port number. It is the standard SSH port.

I cannot get the drive to mount, and I don't know the syntax to force it to mount even when there are errors.

I have 4 partitions no a single HD. The first 3 have errors, and the 4th (/home) has no errors(bad blocks). I can run reiserfsck /dev/hda? on each of the partitions without mounting them. I believe this just does a check, and on hda1, 2, & 3 it gives me the errors mentioned above with 5-10 cannot read from sector, and (Error Uncorrectable), then it finally says bad block (###) could be hardware problem.

Hope this helps,
Rkane
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
bad blocks bong.mau Linux - General 1 11-16-2005 02:17 PM
ReiserFS with bad blocks bruce ford Linux - Software 2 07-23-2005 04:15 AM
Bad blocks - reiserfs corrupted babis Linux - Hardware 3 04-03-2005 09:05 PM
ReiserFS - Bad Blocks - Recovery - HELP! leprechaun Linux - Hardware 1 04-10-2004 07:13 PM
fsck many bad blocks mjolnir *BSD 5 01-13-2004 06:35 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 10:32 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration