LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-15-2009, 10:30 AM   #1
bogwato
LQ Newbie
 
Registered: Jul 2009
Posts: 4

Rep: Reputation: 0
Intrusion attack


Hi

I have hosting with vps server with plesk fedora 8. This evening all domains on my server went down and i did contact with the support. they say i got smpt dos attack and they null routed. after that i login to my server with ssh and i found this log

login as: root
root@ip's password:
Last login: Wed Jul 15 09:42:32 2009 from 203.193.165.78
[root@vpsbox ~]#

and it is definitely not my ip and i did some research on that ip. I found out some bad news about this ip and originated from india. How can i know what they did to my box ?? they did get my root password ?? thank in advance .
 
Old 07-15-2009, 01:20 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
If I get from this that you logged in over the network as root then you made a mistake.

What you can find on your machine depends on a few things like if you have off-site backups, what your distro+version is, what services were running, what you installed in terms of intrusion detection / integrity checking, what root was allowed to do between compromising the host and you restricting access to it. What you can do now is listed in the post here: http://www.linuxquestions.org/questi...96#post3608496. But please reply in this thread, not there.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Intrusion Attempts keysorsoze Linux - Security 7 02-06-2006 01:13 PM
Intrusion Problem!! InvisibleSniper General 7 01-26-2006 09:31 AM
intrusion detection fakie_flip Linux - Security 4 08-19-2005 05:24 PM
intrusion? tincat2 Linux - Security 2 01-01-2005 01:56 AM
Intrusion Detection? matador Linux - Security 5 09-03-2003 04:44 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:42 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration