Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
 Post subject: server hacked, need help
PostPosted: Thu Feb 11, 2010 7:31 pm 
Offline
Junior Member

Joined: Thu Dec 18, 2008 12:33 pm
Posts: 27
Hi guys, à

My server has been hacked, I did a netstats and my server is attempting to contacts ftps around the world every 30 seconds,

I changed my root account, I most likely got the gumblar virus, how can I stop this thing ?!


Is that a cron job?


Top
   
PostPosted: Thu Feb 11, 2010 11:23 pm 
Offline
Senior Member

Joined: Tue Apr 27, 2004 5:10 pm
Posts: 212
Karnius wrote:
Hi guys, à

My server has been hacked, I did a netstats and my server is attempting to contacts ftps around the world every 30 seconds,

I changed my root account, I most likely got the gumblar virus, how can I stop this thing ?!


Is that a cron job?


1. Shut it down now.
2. Take an image of it for future forensic investigation.
3. Rebuild from scratch or from a known-good backup.

That's really all you can do when you get rooted, as you, in most circumstances, have no way of knowing what exactly the perpetrator did to your server.


Top
   
 Post subject:
PostPosted: Thu Feb 11, 2010 11:54 pm 
Offline
Senior Member
User avatar

Joined: Sun Aug 10, 2008 11:26 am
Posts: 104
Location: ~$
It's worth mentioning that gumblar propagates by infecting Windows machines with malware that steal stored passwords for FTP programs, Dreamweaver and such. So make sure you've changed your passwords and disinfected any Windows machines where you stored them, before rebuilding the server.


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 4 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group