
09-20-2006, 06:02 AM
|
|
Web Hosting Evangelist
|
|
Join Date: Mar 2005
Posts: 521
|
|
My Server Is Hacked!!
Hello
I have a dedicated server, it is hacked  , is there anyone who can help me to investigate how they have penetrant to my server?>
Please help.
thanks
|

09-20-2006, 07:04 AM
|
|
WHT Addict
|
|
Join Date: Feb 2006
Posts: 109
|
|
what do u mean with hacked !!!!!!!
they got root access !!!
or just defaced a website or changed something !!!
please provide the following info :
uname -r
...................
last
is there is any logins thats not you !!
....................
history
and
cat /root/.bash_history
and also check if there is any commands executed not by you
|

09-20-2006, 07:11 AM
|
|
Web Hosting Evangelist
|
|
Join Date: Oct 2004
Location: India
Posts: 491
|
|
How you concluded that the server got hacked ?
__________________
ESC :wq!
|

09-20-2006, 07:55 AM
|
|
Web Hosting Evangelist
|
|
Join Date: Mar 2005
Posts: 521
|
|
Thanks for your help
the 2.6.9-34.0.2.ELsmp in the resul of uname -r
and teher are some command that I have not executed and don't know what they do. would you please tae a look at them?
echo /dev/null > /proc/sys/kernel/core_pattern
Modify /etc/sysctl.conf
pico /etc/sysctl.conf
mount -o remount,noexec,nosuid /proc
pico /etc/fstab
lynx -source http://go-pear.org/ | php
pear install Mail
pear install Net_SMTP
Thanks
|

09-20-2006, 07:59 AM
|
|
Web Hosting Evangelist
|
|
Join Date: Mar 2005
Posts: 521
|
|
Thanks for yout help
This is the uname -r result is 2.6.9-34.0.2.ELsmp
and I checked the bach history and there were some command that I have not executed.
would you please taka a look at them?
echo /dev/null > /proc/sys/kernel/core_pattern
Modify /etc/sysctl.conf
pico /etc/sysctl.conf
mount -o remount,noexec,nosuid /proc
pico /etc/fstab
lynx -source http://go-pear.org/ | php
pear install Mail
pear install Net_SMTP
Thanks
|

09-20-2006, 08:02 AM
|
|
Web Hosting Evangelist
|
|
Join Date: Oct 2004
Location: India
Posts: 491
|
|
Seems that someone hardened the server and installed net-snmp to monitor the server bandwidth usages to me. Ask your DC if they did anything on your server.
__________________
ESC :wq!
|

09-20-2006, 02:29 PM
|
|
Junior Guru
|
|
Join Date: May 2006
Posts: 232
|
|
Which company do you have a dedicated server on? I don't think my dedicated server company would ever install anything without my authorization first.
What made you conclude that you were hacked? Is it because you logged in and saw that the last login IP wasn't yours? (Do you have root logins disabled?)
__________________
I'm female.
|

09-20-2006, 04:53 PM
|
|
Web Hosting Master
|
|
Join Date: Mar 2006
Posts: 644
|
|
Are you facing any low performance on the server or malicious activity taking place?
__________________
Live Your DreamZ
~Besty
|

09-20-2006, 05:55 PM
|
|
Performance Specialist
|
|
Join Date: Dec 2004
Location: New York, NY
Posts: 10,341
|
|
__________________
MediaLayer, LLC - Lightning fast web hosting since 2005. Ask about our new pure SSD storage platform!
›› First and leading provider of LiteSpeed based hosting combined with enterprise grade hardware.
›› Free Account Migrations, Custom Solutions, and Servers in US, EU, and Asia
›› Our Application Hosting plans outperform the typical VPS. Ask us about special offers on yearly plans!
|

09-20-2006, 05:57 PM
|
|
WHT Addict
|
|
Join Date: Feb 2006
Posts: 109
|
|
he still didn't explain .... what happend to make him say its hacked !!
|

09-21-2006, 06:03 AM
|
|
Web Hosting Evangelist
|
|
Join Date: Mar 2005
Posts: 521
|
|
the group that has hacked us has informed us and has upload a file on all our accounts on my server,
Thast why I think it is hacked, but I don't think wheather he has the root access because if so he would deffenetely change the password.
I just want to know how he has entered our server and uploaded that files on the server.
Thanks for your replies 
|

09-21-2006, 10:31 AM
|
|
WHT Addict
|
|
Join Date: Feb 2006
Posts: 109
|
|
what type of files he uploaded !!!
a deface like hacked by..............
are you using PhpSuexec or running apache as nobody
are turning SafeMode on or not !!
|

09-21-2006, 11:45 AM
|
|
Junior Guru
|
|
Join Date: May 2006
Posts: 232
|
|
Quote:
|
Originally Posted by IRLAMP
the group that has hacked us has informed us and has upload a file on all our accounts on my server,
Thast why I think it is hacked, but I don't think wheather he has the root access because if so he would deffenetely change the password.
I just want to know how he has entered our server and uploaded that files on the server.
Thanks for your replies 
|
Have you confirmed that those files exist?
Honestly, most hackers won't tell you their backdoors. Just secure your system as best as you can or hire a company to do so.
__________________
I'm female.
|

09-21-2006, 08:44 PM
|
|
learning is in the doing
|
|
Join Date: Sep 2000
Location: Alberta, Canada
Posts: 3,109
|
|
Sounds like a site defacement situation for every/most accounts on the Server.
Login to shell and run this command: /scripts/hackcheck
If it returns the following you are OK, sort of.
findutils passes checksum
net-tools passes checksum
Anything else means your Server has been rooted (taken over by someone else) and your only recourse is an OS reload. If your Server has not been rooted, should take about 2 hrs. for an experienced person to find and remove the hacker files and harden your Server security.
__________________
• PotentProducts.com - for all your Hosting needs
• Helping people Host, Create and Maintain their Web Site
• ServerAdmin Services also available
|

09-22-2006, 04:49 AM
|
|
Web Hosting Guru
|
|
Join Date: Nov 2005
Location: Palma de Mallorca, Spain
Posts: 259
|
|
Quote:
|
Originally Posted by Website Rob
Login to shell and run this command: /scripts/hackcheck
If it returns the following you are OK, sort of.
findutils passes checksum
net-tools passes checksum
|
I was wondering how this "hackcheck" script goes with every linux distribution, but not in my CentOS 4.4  What Linux/Unix do you have? 
|
| Thread Tools |
Search this Thread |
|
|
|
| Display Modes |
Linear Mode
|
| Postbit Selector |
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
|
|
|
| Login: |
|
|
| Advertisement: |
|
|
| Web Hosting News: |
|
|
|