Koozali.org: home of the SME Server

securuty : a hacker's attack on my sme server 5.1.2

doumebzh

securuty : a hacker's attack on my sme server 5.1.2
« on: November 11, 2004, 02:16:21 PM »
Hello
After problems http on my server, I open a ssh shell from outside my local network. I was looking at new files unknown on /, an then I see like a chat on my shell (see above what said the hacker).
Anyone has an idea on the way he attacked my server, an how I can avoid that anymore??

[root@zouave spool]# come on answer me ..
[root@zouave spool]# j'ai beison de un psybnc
j nai'pas un server
> mon francais et bad
what is try write root
pbsyncups
?try write hax0r
[root@zouave spool]# answer
Irepone                                                                      
lalalalaalala
lalalalallalala
mail vampix@apofish.org ..
et reponde ..
[root@zouave spool]# bye bye
EOF

Offline CharlieBrady

  • *
  • 6,918
  • +3/-0
Re: securuty : a hacker's attack on my sme server 5.1.2
« Reply #1 on: November 11, 2004, 04:26:07 PM »
Quote from: "doumebzh"
Hello
Anyone has an idea on the way he attacked my server, an how I can avoid that anymore??


5.1.2 is very old, and all users have been recommended to upgrade for a long time now. It is no big suprise that the server has been compromised. You'll need to do a fresh install, of an up to date version.