Re: Somebody is hacking me; what to do?

1999-11-13 Thread Kevin Heath
On Fri, Nov 12, 1999 at 02:31:35PM -0900, Christopher S. Swingley wrote: > The only way to be sure you've removed all backdoors and compromised > files is is to disconnect from the net, format all of your drives > and reinstall from scratch. >[...] > Probably sounds like overkill, but when all is s

Re: Somebody is hacking me; what to do?

1999-11-12 Thread Christopher S. Swingley
The only way to be sure you've removed all backdoors and compromised files is is to disconnect from the net, format all of your drives and reinstall from scratch. Once the system is running, apply any security patches and lock down your box (/etc/hosts.deny = ALL: ALL, /etc/hosts.allow = ALL: loca

Re: Somebody is hacking me; what to do?

1999-11-12 Thread Kevin Heath
On Fri, Nov 12, 1999 at 05:39:01PM -0500, Kevin Heath wrote: >[...] > I'm probably forgeting lots of things. Yup--you should probably first install the debsums package to see what files don't match their original checksum: "debsums -sa 2>&1 |tee -a dubsum.log" Also, make sure root's .profile, .b

Re: Somebody is hacking me; what to do?

1999-11-12 Thread Kevin Heath
On Fri, Nov 12, 1999 at 09:22:54PM +0200, Daniel Mashao wrote: > I am getting emails from some fool saying > Ifwewerehackerswedownyourdumbass > which means "If we were hackers we down your dumb ass" >[...] > Any advice for me? Physically diconnent the box from the network. Reinstall all th

Somebody is hacking me; what to do?

1999-11-12 Thread Daniel Mashao
I am getting emails from some fool saying Ifwewerehackerswedownyourdumbass which means "If we were hackers we down your dumb ass" The emails are generated from within my system. The problem started when I logged into one of my old machines and ran "last -10". I was suprised to see a user