Re: Urgent!!! My computer seems to be hacked, pls HELP!!!



"René Berber" typed:
Todd H. wrote:
Yup. It's the only way to get back to a known state. Wiping and
reinstalling from original media.

But that's not needed, you can find which process is using that
particular port and kill it (use lsof). Then run a rootkit
detection and/or anti-virus detection to try to find out where that
process came from (there are several to choose from). Before that I
would harden ssh access, no access except your user.

Reinstalling (and rebuilding) a system is far easier and quicker than
figuring out how deep and thorough the compromise is and cleaning the
system to some reasonable extent.

--
Ayaz Ahmed Khan

Then, gently touching my face, she hesitated for a moment as her
incredible eyes poured forth into mine love, joy, pain, tragedy,
acceptance, and peace. "'Bye for now," she said warmly.
-- Thea Alexander, "2150 A.D."

.



Relevant Pages

  • Re: Urgent!!! My computer seems to be hacked, pls HELP!!!
    ... would harden ssh access, ... Reinstalling a system is far easier and quicker than ... install, but for the dozens or perhaps hundreds of other ...
    (comp.security.ssh)
  • Re: AW: nouser - rootkit ?
    ... > bright enough to find the rootkit, I sure do hope that he also realizes that ... than reinstalling it really should stop. ... > For more information on this free incident handling, management ... > and tracking system please see: http://aris.securityfocus.com ...
    (Incidents)
  • Re: think I may have been rootkitted
    ... In these directories I found the hackers rootkit and ... I ended up reinstalling because I could not get some of ... the rpms to reinstall. ...
    (comp.os.linux.security)
  • Re: think I may have been rootkitted
    ... In these directories I found the hackers rootkit and ... I ended up reinstalling because I could not get some of ... the rpms to reinstall. ...
    (comp.os.linux.security)