[ubuntu-uk] off topic - server security

Alan Pope alan at popey.com
Thu Dec 27 19:13:13 GMT 2007


On Thu, Dec 27, 2007 at 07:34:23AM +0000, Sean Miller wrote:
> I am aware this isn't Ubuntu related, but I'm tearing my hair out.
> 
> For the past week or so some folks have been constantly hacking my
> webserver... it's running Cent-OS I believe, but I don't have the knowledge
> to work out how they're getting in.
> 

First thing I'd do is shut it down and restore from backup. You have 
discovered that no matter how much you clean up there's no way you can be 
sure they cant get in again. 

Make sure you have up to date secure versions of all installed web apps. If 
processes are owned by apache then chances are its a compromised script 
running on the site that they are getting in through. 

Cheers,
Al.



More information about the ubuntu-uk mailing list