Koozali.org: home of the SME Server

Help please

ADG

Help please
« on: December 16, 2004, 09:56:37 PM »
Anyone interested in a bit of 'forensic investigation'?

Someone got into my web site ..

I'm a complete numpty about linux/internet and suspect that they got in because of something silly i've done, but I need to find out how they got in, what they've done and what I need to do to fix it.

if this interests you, send me an email at bron AT emailme.com.au .. i'd love some help.


Bron
(if this breaches forum rules, can you delete it?)

Offline mrjhb3

  • *
  • 1,188
  • +0/-0
    • John Bennett Services
Help please
« Reply #1 on: December 17, 2004, 02:33:03 AM »
Look in your /var/log/messages and see if you can spot something.  Search these forums for the unofficial update script and install some or all of the components.  I at least recommend the rkhunter then run it and see what it reports.
......

ADG

Help please
« Reply #2 on: December 17, 2004, 06:23:53 AM »
They deleted the /var/log directory and all subdirectories, do you know how to undelete in Linux?

Offline mrjhb3

  • *
  • 1,188
  • +0/-0
    • John Bennett Services
Help please
« Reply #3 on: December 17, 2004, 01:59:14 PM »
No, I sure don't, sorry.
......

Offline BoZz

  • ***
  • 48
  • +0/-0
Help please
« Reply #4 on: December 17, 2004, 02:10:30 PM »
hmmmmmmmm time for a new box but you could install rkhunter which might show you what type of root kit was used. It can be found here http://mirror.contribs.org/smeserver/contribs/dthomas/smeserver/6.x/Contrib/rkhunter/smeserver-rkhunter-1.1.8-1.noarch.rpm

guest22

Help please
« Reply #5 on: December 17, 2004, 07:16:21 PM »
Please mail ALL security related issues to security AT contribs.org with as much details as possible.

Thanks,
RequestedDeletion

ADG

Help please
« Reply #6 on: December 17, 2004, 10:17:19 PM »
I am initially trying to undelete the security logs, not sure if that will work though as i've rebooted the server already.  But today i'm going to drag the hdd out and put it in a Windows box and see whether I can get anything back.

I have nothing at the moment that indicates how they got in or what they did other than change the index.*'s on the site and delete the log files.