Tycoon Talk
Become a Big fish!
The number 1 forum for online business!
Post topics, ask questions, share your knowledge.
Tycoon Talk is part of Freelancer.com - find skilled workers online at a fraction of the cost.

Website and Server Administration Forum


You are currently viewing our Website and Server Administration Forum as a guest. Please register to participate.
Login



Reply
Yay, It's my first time... :-((
Old 02-12-2009, 10:41 AM Yay, It's my first time... :-((
tripy's Avatar
Do not try this at home!

Posts: 3,621
Name: Thierry
Location: I'm the uber Spaminator !
Trades: 0
Well, today is the day
The first time in 10 years that one of my server has been compromised.

My dedicated server started DOSing the embassy of Brazil, here, in Switzerland.
Sheesh, this is annoying....
__________________
Only a biker knows why a dog sticks his head out the window.
tripy is offline
Reply With Quote
View Public Profile Visit tripy's homepage!
 
 
Register now for full access!
Old 02-12-2009, 06:25 PM Re: Yay, It's my first time... :-((
andrei155's Avatar
CEO of BLD Hosting

Posts: 1,514
Name: Andrei
Location: Canada
Trades: 6
How did you figure out you were being used?
__________________
No Overselling Guarantee
Now Includes a Free Domain
BLD Hosting -
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE
andrei155 is offline
Reply With Quote
View Public Profile Visit andrei155's homepage!
 
Old 02-12-2009, 07:38 PM Re: Yay, It's my first time... :-((
tripy's Avatar
Do not try this at home!

Posts: 3,621
Name: Thierry
Location: I'm the uber Spaminator !
Trades: 0
when I've got disconnected from my ssh session, and that each ping takes 5 seconds between them, but with a round trip of 16 ms, I knew it was not my connection that had a problem.

And a couple of hours later, after I sent the data center a mail, they told me that there was a DOS occurring.
But what surprised me is when he told me that it came from my server.

My data center gave me back ssh access (and ssh only), and I spent the evening trying to find where they entered, but with no extends.
I have no idea how they got in, and that pisses me off.

I hope I covered it by changing the certificates, keys, and removed the sudo with no password policy.
I've just recompiled a new kernel, so if they got the old one tainted, it should do the trick.

And this time, I will run tripwire. It takes a checksum of the most vitals file and report each changes in size, date/time and owner.
The only problem is that I'm not sure that the current system state is "clean".
__________________
Only a biker knows why a dog sticks his head out the window.
tripy is offline
Reply With Quote
View Public Profile Visit tripy's homepage!
 
Old 02-12-2009, 11:22 PM Re: Yay, It's my first time... :-((
andrei155's Avatar
CEO of BLD Hosting

Posts: 1,514
Name: Andrei
Location: Canada
Trades: 6
What was the server being used for?
__________________
No Overselling Guarantee
Now Includes a Free Domain
BLD Hosting -
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE
andrei155 is offline
Reply With Quote
View Public Profile Visit andrei155's homepage!
 
Old 02-13-2009, 04:11 AM Re: Yay, It's my first time... :-((
tripy's Avatar
Do not try this at home!

Posts: 3,621
Name: Thierry
Location: I'm the uber Spaminator !
Trades: 0
Quote:
What was the server being used for?
Mail, db, ldap, subversion repository, my screenshoting web service and a few web sites where on it.
__________________
Only a biker knows why a dog sticks his head out the window.
tripy is offline
Reply With Quote
View Public Profile Visit tripy's homepage!
 
Old 02-13-2009, 08:32 AM Re: Yay, It's my first time... :-((
andrei155's Avatar
CEO of BLD Hosting

Posts: 1,514
Name: Andrei
Location: Canada
Trades: 6
and what happened to the service and those websites?
__________________
No Overselling Guarantee
Now Includes a Free Domain
BLD Hosting -
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE
andrei155 is offline
Reply With Quote
View Public Profile Visit andrei155's homepage!
 
Old 02-13-2009, 08:51 AM Re: Yay, It's my first time... :-((
tripy's Avatar
Do not try this at home!

Posts: 3,621
Name: Thierry
Location: I'm the uber Spaminator !
Trades: 0
First, the datacenter restarted the server and turned everything off.
They enabled ssh traffic between the server and 1 ip I gave them, and I am in the process of re-installing everything.

Thanks for gentoo, I can rebuild a bootstrap without much problems.
Most of the base is rebuilt, I am now working with apache, python and such.

I hope the server to be up and running tonight.
__________________
Only a biker knows why a dog sticks his head out the window.
tripy is offline
Reply With Quote
View Public Profile Visit tripy's homepage!
 
Reply     « Reply to Yay, It's my first time... :-((
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off





   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML



Page generated in 0.78343 seconds with 12 queries