LinuxQuestions.org

LinuxQuestions.org (/questions/)
-   Linux - Security (https://www.linuxquestions.org/questions/linux-security-4/)
-   -   Server hacked with phishing files (https://www.linuxquestions.org/questions/linux-security-4/server-hacked-with-phishing-files-768310/)

Rastus 11-10-2009 10:06 PM

Server hacked with phishing files
 
Hello,
My server has been hacked, and I am trying to resolve it. I have been working through the list of security tips here --> http://www.yolinux.com/TUTORIALS/Lin...tSecurity.html < - Up till now, I could delete the folders the hacker created, now I can't, I log in as root and when I try to delete them using rm -rf (directory name) I get permission denied. that's the most urgent thing I need help with.. my hacker is smarter than me it would appear, which right now is not saying much, then I need to find out hopw he got in and is still getting in.. this is a dedicated server running Redhat EL 4.6-32. Hope all that made sense.. I'm kinda stressed right now..

any help or insight offered is greatly appreaciated.
Kenny

unixfool 11-10-2009 10:24 PM

I'm gonna say to try the standard and highly recommended CERT Intrusion Checklist first before doing anything else...and ignore recommendations to immediately reinstall your distribution, as you'd only get rehacked...the object is to learn how the server got cracked and learn from the experience.

Rastus 11-10-2009 10:51 PM

Thanks.. going there now


All times are GMT -5. The time now is 03:04 PM.