Re: compromised server

From: Joe Warner (rootman22_at_comcast.net)
Date: 08/29/03

  • Next message: hutchens: "testing"
    To: jahmon <jahmon@jahmon.com>, freeBSD-security@freebsd.org
    Date: Fri, 29 Aug 2003 06:38:12 -0600
    
    

    Hi Jahmon,

    I'd highly recommend you try The Coroners Toolkit (TCT):

    http://www.porcupine.org/forensics/tct.html

    Take a look at "Help! Someone has broken into my system!'

    http://www.fish.com/tct/help-when-broken-into

    ..at the bottom of the page.

    Good luck,

    Joe

    On Thursday 28 August 2003 08:41 am, jahmon wrote:
    > I have a server that has been compromised.
    > I'm running version 4.6.2
    > when I do
    >
    > >last
    >
    > this line comes up in the list.
    > shutdown ~ Thu Aug 28 05:22
    > That was the time the server went down.
    > There seemed to be some configuration changes.
    > Some of the files seemed to revert back to default versions
    > (httpd.conf, resolv.conf)
    >
    > Does anyone have a clue what type of exploit they may have used?
    > Is there anyway I can find out if there are any trojans installed?
    >
    > Thanks
    >
    > jahmon
    >
    > _______________________________________________
    > freebsd-security@freebsd.org mailing list
    > http://lists.freebsd.org/mailman/listinfo/freebsd-security
    > To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"

    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: hutchens: "testing"

    Relevant Pages

    • Re: Curious about top posts
      ... >> You don't read a book or newspaper article from bottom to ... so why would you set-up your newsgroup post that way? ... The fundamental architecture of Usenet is ... from server to server, eventually arriving on someone else's server ...
      (alt.tv.survivor)
    • Re: match machine name to user name
      ... :>: query the server from a client for a username based on a machine name. ... :> It reads better if you post inline or at the bottom. ... Is it better to use the script to poll the server or to ...
      (microsoft.public.scripting.vbscript)
    • socket ... how can I ... ?
      ... frame .bottom ... pack .bottom -side bottom -fill x ... proc Server {channel clientaddr clientport} { ...
      (comp.lang.tcl)
    • Re: Go Daddy
      ... button on the bottom that when I choose "Use the Same as the Incoming ... Server" it will not stay checked. ... they assure me that I have my settings correct. ...
      (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
    • Re: ** HELP ** STUMPED!!!!
      ... check your firewall rules Is ISA blocking DHCP? ... To cut a long story short, I got to the bottom of the ... code again so I called the client and asked them to use the verify option ... through saying reset server, check router yadayada.. ...
      (microsoft.public.windows.server.sbs)