Koozali.org: home of the SME Server

Legacy Forums => General Discussion (Legacy) => Topic started by: doumebzh on November 11, 2004, 02:16:21 PM

Title: securuty : a hacker's attack on my sme server 5.1.2
Post by: doumebzh on November 11, 2004, 02:16:21 PM
Hello
After problems http on my server, I open a ssh shell from outside my local network. I was looking at new files unknown on /, an then I see like a chat on my shell (see above what said the hacker).
Anyone has an idea on the way he attacked my server, an how I can avoid that anymore??

[root@zouave spool]# come on answer me ..
[root@zouave spool]# j'ai beison de un psybnc
j nai'pas un server
> mon francais et bad
what is try write root
pbsyncups
?try write hax0r
[root@zouave spool]# answer
Irepone                                                                      
lalalalaalala
lalalalallalala
mail vampix@apofish.org ..
et reponde ..
[root@zouave spool]# bye bye
EOF
Title: Re: securuty : a hacker's attack on my sme server 5.1.2
Post by: CharlieBrady on November 11, 2004, 04:26:07 PM
Quote from: "doumebzh"
Hello
Anyone has an idea on the way he attacked my server, an how I can avoid that anymore??


5.1.2 is very old, and all users have been recommended to upgrade for a long time now. It is no big suprise that the server has been compromised. You'll need to do a fresh install, of an up to date version.