Charlie,
My thoughts EXACTLY - Except for one thing. In the madness of an organisation being down (one full of computer controlled lathes etc that need files from the network etc) and me seemingly having no configuration settings, a flu headache and not having a clue what the internet settings were (all written down and safely stored 100kms away :-{) a flash of inspiration struck!
"I will get the configuration from the database" - it hadnt occured to me that the configuration was "lost" - it doesnt read like I mean trust me. I did think they were lost - but years of computers have told me when the crisis stikes use 50% logic 50% instinct... Worry about why LATER.
So I did a /sbin/e-smith/db configuration show >14Mar05Configuration.txt and re-entered the settings by reading my dump of the settings - so surely they were not lost! Why was I asked for all of them?
So I think you can now see why i have NFI why this all happened, and am now inclined to beleive I stumbled into a trap and it had nothing to do with dnscache at all.
Did someone say hacked? I must admit one of todays activity is to go and run some rootkit tools and look around... but dare I say ... the machine doesnt FEEL hacked - some readers will know what I mean others will perhaps want to flame me - please dont bother....
Certainly the logs show plenty of attempts - like all servers, and there is no sudden change in diskspace or other stats... I know this doesnt mean definitely not hacked... Anyway I will check today.
Any other things you can think of Charlie?
I would love a tool that checked the configuration database - yes the dump followed by a read in less would seem enough - but in this case it wasnt...
I am still damaged by the whole affair
