LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 09-25-2014, 07:50 AM   #1
anon091
Senior Member
 
Registered: Jun 2009
Posts: 1,795

Rep: Reputation: 49
What if scenario: what if vsftp server was compromised, what do you do?


Hi everyone. Was just thinking about hypothetical bad situations that could happen. Say you have a vsftp server and it got compromised, what would you do after you remove it from the network?
 
Old 09-26-2014, 05:38 AM   #2
ilesterg
Member
 
Registered: Jul 2012
Location: München
Distribution: Debian, CentOS/RHEL
Posts: 587

Rep: Reputation: 72
It would really depend on what the issue is about. Root access compromised? missing files? unknown files just popping out of knowhere? unknown processes just kicking off even if you kill it?
 
Old 09-26-2014, 07:22 AM   #3
chrism01
LQ Guru
 
Registered: Aug 2004
Location: Sydney
Distribution: Rocky 9.2
Posts: 18,359

Rep: Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751
You'd definitely want to figure out why it was compromised, but as above, you'd need to start with the evidence.
Ideally, take an exact copy & mount it as a data disk(s) on another system for read only access.

If you really need to get a replacement back online stat, then rebuild from scratch using known good sources, upgrade to the latest of everything you can and add on some security tools/monitoring and keep a very strict eye on it.


Can't really give specific advice without a specific example; definitely read the Stickies on the Security forum.
 
Old 09-26-2014, 08:44 AM   #4
anon091
Senior Member
 
Registered: Jun 2009
Posts: 1,795

Original Poster
Rep: Reputation: 49
OK, I was more just thinking in general when I had the post, but I guess you're right, since there's so many ways it could get compromised.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Server compromised? sminogue Linux - Security 2 12-15-2011 01:54 PM
server compromised? eco Linux - Security 3 09-03-2010 11:58 AM
my server has been compromised, what next? Kropotkin Linux - Security 15 08-27-2009 06:15 AM
Server Compromised? stlyz3 Linux - Security 6 09-07-2005 04:28 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 01:19 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration