Paul wrote:
>
> found this in my "View Log File: httpd/admin_error_log"
>
> Warning: Permanently added the RSA1 host key for IP address
> '66.37.211.36' to the list of known hosts.
>
> Definately not of my doing. Do'es this mean someone got in
> via SSH ?
>
> server is 5.1.2, just built that day as a test and was still
> being setup when this entry appeared.
Firstly if you ever believe you have been hacked a public bulletin board is not the appropriate place to post this type of message.
The entry is due to someone connecting to an external address, 66.37.211.36, so Im not quite sure how you got the idea you were hacked.
The address is used by the blades mechanism which uses ssh, it's quite safe.
--
Damien