RE: Visited by a cracker
Mario Ohnewald <[email protected]>
| Newsgroups | gmane.comp.security.linux |
|---|---|
| Message-ID | <[email protected]> |
On Wed, 2004-07-14 at 20:10, Shay Wilson wrote: > I'm a little confused. There have been several suggestions to wipe the > box and I'm not disagreeing, but there was no sign of any successful > hack. You will _never_ know for sure... > The cracker was given a shell by the administrator. He paid for it > (with a stolen credit card). I realize approaching the machine with > caution and using administrative tools that are verified perhaps freshly > installed from on a CD or another machine is a very good thing, but > wiping the machine? Use your backup. You do have a backup on such an important production system, dont you? > > If I wiped my production machines every time my logs showed that someone > attempted to gain unauthorized access or elevate their privileges I'd > never have a working machine. In fact within minutes of turning a > machine on I'm hit with various malevolent apache requests of someone > trying to gain access through an old exploit. No need, to panic, just keep an eye on it. But this is diffrent to your case, where someone actually was IN your system. > > > Granted these were newer exploits and potentially more dangerous because > a shell had already been granted. They were still patched against and > unsuccessful. Why must we wipe? To be _sure_. I couldn't sleep until its wiped out.