Re: unknown process

From: Peter Pentchev (roam@orbitel.bg)
Date: 04/19/01


Date: Thu, 19 Apr 2001 12:39:15 +0300
From: Peter Pentchev <roam@orbitel.bg>
To: Dag-Erling Smorgrav <des@ofug.org>

On Thu, Apr 19, 2001 at 11:31:26AM +0200, Dag-Erling Smorgrav wrote:
> "David G. Andersen" <dga@pobox.com> writes:
> > You've been hacked. Do what Kris said immediately - take your
> > system offline, and figure out how they got in. You'll likely
> > need to either restore from backups, a fresh install, or check
> > your tripwire/etc logs to determine what else the intruder
> > changed, if they installed a rootkit, etc.
>
> It's not either/or. The only acceptable solution to this situation is
> a complete reinstall from a trusted source (e.g. original CD set).

..and during the install, examine your backups - people have been known
to restore systems from backup, only to find out that the intrusion had
happened *before* the backup; sometimes there are months and months of
accurately backed up backdoors and stuff.

G'luck,
Peter

-- 
Thit sentence is not self-referential because "thit" is not a word.
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message


Relevant Pages

  • Re: FreeBSD for the common man(or woman) (was: > upgrade 7.2
    ... few steps to be taken, such as install it, set up which printer you ... I wanted to backup the client computers to the server. ... That's why you have a UNIX server for backups. ... since my Linux clients do things a little differently. ...
    (freebsd-questions)
  • Re: Recovering from compromised system
    ... > My RH8 system was hardened by Bastille, but I apparently forgot to install ... > decided that RHN was down. ... > After booting a diskette and restoring from a clean backup, ... > salvage some data from backups of the compromised system. ...
    (comp.os.linux.security)
  • Re: SBS 2003 missing file associations after uninstalling ArcServe
    ... registry from the repair folder in Windows. ... SBS or ArcServe install from day one. ... Agree with you Claus re backups, ... >>> after doing so the file associations in the registry got screwed up. ...
    (microsoft.public.windows.server.sbs)
  • Recovering from compromised system
    ... My RH8 system was hardened by Bastille, but I apparently forgot to install ... After booting a diskette and restoring from a clean backup, ... salvage some data from backups of the compromised system. ...
    (comp.os.linux.security)
  • Re: Maintain XP without problems
    ... I have had problems with upgrades in the ... I am going to use Chrome or foxfire so I do not plan on ... cards - so there have been repair installs, ... Backups are a big thing. ...
    (microsoft.public.windowsxp.general)