LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 04-07-2011, 03:26 AM   #1
jasonchongkn@hotmail.com
LQ Newbie
 
Registered: Apr 2011
Posts: 3

Rep: Reputation: 0
centos 5 hacked again


help, please

my server is web server with centos 5 & parallel 9, don't why all web sites in this server have been added a home pages which is not mind. even the mysql admin also redirected to other site, what i can do!!!!!
I am a newbie of linux!

please help
 
Old 04-07-2011, 03:39 AM   #2
business_kid
LQ Guru
 
Registered: Jan 2006
Location: Ireland
Distribution: Slackware, Slarm64 & Android
Posts: 17,516

Rep: Reputation: 2604Reputation: 2604Reputation: 2604Reputation: 2604Reputation: 2604Reputation: 2604Reputation: 2604Reputation: 2604Reputation: 2604Reputation: 2604Reputation: 2604
Congrats on finding out that much.
I would look for the local Linux User Group and seek help. Fixing the box isn't enough - you would have to fix the vulnerabilities.
 
Old 04-07-2011, 04:29 AM   #3
jschiwal
LQ Guru
 
Registered: Aug 2001
Location: Fargo, ND
Distribution: SuSE AMD64
Posts: 15,733

Rep: Reputation: 683Reputation: 683Reputation: 683Reputation: 683Reputation: 683Reputation: 683
You might want to report your thread and ask it to be moved to the Linux Security forum.

Read through previous threads in the Linux Security forum so you know what information you need to gather to proceed.

For example, the link to the Intruder Detection Checklist on this sticky post may be a good place to start:
http://www.linuxquestions.org/questi...erences-45261/

The MySQL manual has a security section. There are a couple of things you MUST do after installing.

Mostly you will need to gather and study the logs for the kernel, and the web server, and check your configuration settings and permissions. You need to learn how your systems were compromised so you can correct the situation before going back on line.

Sorry but I don't know what parallel 9 is. You might want to explain what it is if it may have vulnerabilities.

Last edited by jschiwal; 04-07-2011 at 04:30 AM.
 
Old 04-07-2011, 12:01 PM   #4
Noway2
Senior Member
 
Registered: Jul 2007
Distribution: Gentoo
Posts: 2,125

Rep: Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781
From reading the original post, it also looks like it could be a case of domain squatting, rather than a compromised host.

Perform an nslookup of your domain and see if it returns your public IP address. Be sure to use a DNS server that is not yours, like Google's public DNS.
To do this, launch a terminal prompt and code the following:

Code:
nslookup
server 8.8.8.8
<your-domain>
If you get something back other than your public IP address, you need to contact your domain registrar.
 
Old 04-07-2011, 10:36 PM   #5
jasonchongkn@hotmail.com
LQ Newbie
 
Registered: Apr 2011
Posts: 3

Original Poster
Rep: Reputation: 0
thanks you everybody!

i mean parallel control panel 9
 
Old 04-08-2011, 04:41 AM   #6
jschiwal
LQ Guru
 
Registered: Aug 2001
Location: Fargo, ND
Distribution: SuSE AMD64
Posts: 15,733

Rep: Reputation: 683Reputation: 683Reputation: 683Reputation: 683Reputation: 683Reputation: 683
Thank you jasonchongkn. I thought the links in his own site had been modified.
 
Old 04-09-2011, 11:47 AM   #7
jasonchongkn@hotmail.com
LQ Newbie
 
Registered: Apr 2011
Posts: 3

Original Poster
Rep: Reputation: 0
Wink

thanks jschiwal, could you tell how to prevent this issue happen again?
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
CentOS Weird behavior, Maybe I got hacked? [URGENT] AsadMoeen Linux - Server 10 03-01-2011 11:53 AM
[SOLVED] My network is hacked for sure. I want to reinstall but it will be hacked again. MsRefusenik Linux - Security 19 10-18-2010 05:02 PM
aarnet.edu.au Centos 5.3 mirror hacked. mazinoz Linux - Server 1 04-04-2009 05:23 PM
LXer: Install CentOS 5 DomU on CentOS 5 Dom0(64 bit) from NFS share LXer Syndicated Linux News 0 11-09-2007 03:41 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 06:03 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration