Re: my server has been hacked again

2003-05-30 Thread Jeff Lane
We get at least 40-50 attempts per day like that. Most are port scans and such... So far, knock on wood, we havent had any trouble, and seem to be doing well using a mix of iptables/portsentry/ Honestly tho, these repeated scans and attemps from Korea and China and other places that foster th

Re: my server has been hacked again

2003-05-30 Thread Joseph A Nagy Jr
Gordon Messmer wrote: [EMAIL PROTECTED] wrote: 210.90.225.193 and 202.56.215.25. I can still ping these ips. How can I inform the system administrator of respective ips? Use "whois " to find contact info for the address. The first of those is a Korean address, and you're unlikely to find anyon

Re: my server has been hacked again

2003-05-30 Thread Gordon Messmer
[EMAIL PROTECTED] wrote: Hi all, My server RH 7.0 (soon upgrading to 8) has been again hacked vi ftp . Don't upgrade; do a clean install. Copy over your data files, and set up each service again (don't blindly use the config files or password files from the hacked machine). 210.90.225.193 and

Re: my server has been hacked again

2003-05-30 Thread Joseph A Nagy Jr
[EMAIL PROTECTED] wrote: Hi all, My server RH 7.0 (soon upgrading to 8) has been again hacked vi ftp . It has been twice and the process is same. They login via ftp (anonymous) user. Chkrootkit program shows ifconfig, ls, netstat, ps, syslogd, tcpd, top, rexedcs infected. Using 'last |grep conn

Re: my server has been hacked again

2003-05-30 Thread John P Verel
On 05/29/03 12:58 -0400, Jeff Lane wrote: > > 1: format and reinstall this machine ...with Red Hat 9! -- redhat-list mailing list unsubscribe mailto:[EMAIL PROTECTED] https://www.redhat.com/mailman/listinfo/redhat-list

Re: my server has been hacked again

2003-05-30 Thread Jeff Lane
More importantly is what he said originally... "My server RH 7.0 (soon upgrading to 8) has been hacked AGAIN vi ftp." This makes me wonder... first off, hes running 7.0. Has he or the admin bothered with keeping the machine up to date with errata and secuirty patches? Next, that makes me ask

Re: my server has been hacked again

2003-05-30 Thread Paul Barclay
Why don't you just use SSH and be done with it! Why use FTP? So 2 decade ago! On Thu, 2003-05-29 at 14:56, Joe Giles wrote: > Or, better yet, use an FTP daemon that is secure and not the stock one > that comes with RedHat (WU-FTP?):-P. I use ProFTPD and I have not had > one problem as of yet

Re: my server has been hacked again

2003-05-30 Thread Joe Giles
Or, better yet, use an FTP daemon that is secure and not the stock one that comes with RedHat (WU-FTP?):-P. I use ProFTPD and I have not had one problem as of yet (Knock on Wood), however, I do like the idea of a chroot jail :-D.. Thanks Joe On Thu, 2003-05-29 at 05:57, Anthony E. Greene wrote:

Re: my server has been hacked again

2003-05-29 Thread Anthony E. Greene
On 29-May-2003/16:53 +0530, [EMAIL PROTECTED] wrote: >My server RH 7.0 (soon upgrading to 8) has been again hacked vi ftp . It >has been twice and the process is same. They login via ftp (anonymous) >user. Do you really need to allow anonymous FTP from all over the Internet? If you don't need this

my server has been hacked again

2003-05-29 Thread nlimbu
Hi all, My server RH 7.0 (soon upgrading to 8) has been again hacked vi ftp . It has been twice and the process is same. They login via ftp (anonymous) user. Chkrootkit program shows ifconfig, ls, netstat, ps, syslogd, tcpd, top, rexedcs infected. Using 'last |grep connected' command, I found 2