Re: lighting---hacked!

From: David (thunderbolt01@netscape.net)
Date: 05/08/02


From: David <thunderbolt01@netscape.net>
Date: Wed, 08 May 2002 16:14:54 GMT

Clayton D. Strand wrote:
> Our server (www.lazotech.com) got hacked. Someone put a program on
> it to change the root password then installed a program called
> BOGUS.root.h2aC which evidently replaced our named. I can't get into
> the system, the command "passwd" from a rescue disk does not work,
> as the actual password files were deleted from the system.

If you can't get into it to make a backup then you can use a root disk
like Tom's root boot disk which is available at the link below to get
the system up to make a backup.

http://www.toms.net/rb/

Or, most distro's include a rescue image on the installation CD to get
the system up to make repairs and/or backups. Boot like doing a new
install and at the boot prompt enter:

   linux rescue

> Is there a convenient fix, or am I hosed, if I understand the
> technical term correctly?

There is no convenient fix to repair a CRACKED system other than wiping
the disk and doing a clean install. This is the only way to be sure no
backdoors and/or changes made to the system were missed.

-- 
   Confucius:  He who play in root, eventually kill tree.
Registered with the Linux Counter.  http://counter.li.org



Relevant Pages

  • Re: Install XP Pro
    ... > partitions of the two HD in the PC (Root C+E+F), ... > A pain because many of these applications were downloaded. ... > I copy my second HD onto the third disk ... > I install the cleaned second HD in the bay where the root was. ...
    (microsoft.public.windowsxp.general)
  • Install XP Pro
    ... I am going to perform a clean install of XP Pro. ... partitions of the two HD in the PC (Root C+E+F), ... I copy my second HD onto the third disk ... I install the cleaned second HD in the bay where the root was. ...
    (microsoft.public.windowsxp.general)
  • Re: How to fix two disks with the same Volume Group?
    ... disk drive was slowly failing. ... need root password then (it seems a little redundant but anyway... ... you'll have to prefix the lvm commands with lvm, ... Is this under repair on the install cd? ...
    (Fedora)
  • Re: No Root password
    ... > find or reset the root password to have access to the box. ... > original install CD or disk, and all of my other computers are MS ... You may be able to gain root access via the service diagnostics if the ... at the "DIAGNOSTIC OPERATING INSTRUCTIONS" prompt press ...
    (comp.unix.aix)
  • Re: minimum requirements
    ... dual boot setup with the 4GB drive being totally allocated to FreeBSD. ... should I use a larger drive to install the many of FreeBSD's features? ... in the big disk, just by changing a line in httpd.conf. ... If you build on the small disk, I would still suggest making root ...
    (freebsd-questions)