Re: Hackers on the web
"A. Davis" <[email protected]>
| Newsgroups | gmane.org.user-groups.linux.morlug |
|---|---|
| Message-ID | <[email protected]> |
Unfortunately this isnt very uncommon. You probably have a crapload of attempts from people trying to login as any name under the sun. Check out http://www.chkrootkit.org/ for a pretty straight forward script that will check alot of common compromises. On Wed, 2005-04-13 at 12:02 -0400, Andrei Smirnov wrote: > I am running a RH7.2 server at home as a gateway to Adelphia's cable > Internet. I recently checked the logs and found a huge number of root > access attempts. I did not really see any suspicious things happening on > that computer except once the external network card disconnected by itself > (that is, somehow did 'ifdown eth1'), but I am not 100% sure if it wasn't > something I accidentally triggered. > > My question is: is there a way to check if my system has been > compromised? > > Should I reinstall/upgrade? >