Koozali.org: home of the SME Server

I think I've been hacked!

Steven

I think I've been hacked!
« on: May 14, 2003, 04:57:10 PM »
When you log on to your server, you get a line that says
Last logged on from......
This now has a michine name that is not part of my network and that I definatly do not know.

Surely this means someone has somehow gained access to my server(I am the only one who knows the password and I have a dynamic Ip Address that changes every 24 hours) How can this be?

Can i make sure and /or see what was done?

Thanks
Steven

guestHH

Re: I think I've been hacked!
« Reply #1 on: May 14, 2003, 05:18:56 PM »
check your log files (and creation date)

report to smesecurity@mitel.com

Craig

Re: I think I've been hacked!
« Reply #2 on: May 14, 2003, 05:19:26 PM »
Log back into the server as root.  Then use the 'last' command.

This will show you when users were last logged in, logged out, how long they were in the system for and date/time and importantly in your case - where they came from.

Using the values that you get you can look in you log files to see if there is any thing in there around the same time.  Look in your .bash_history and see if there is some commands that you don't recognise.

Of course if you have been hacked then there is a high chance that they will be clever enough to cover their own tracks in the files just mentioned and you may never know if you were hacked.

In which case you might want to try a reinstall with a change of password.

Steven

Re: I think I've been hacked!
« Reply #3 on: May 14, 2003, 05:55:30 PM »
Thanks Guys, but I'm an idiot!
That was putty which I use from my PC to access the server, but it's very strange that it shows that I logged on from another (real) domain, and also it only started doing that at 9 this morning (from "last"command), before which it used my ip address, and there are some logons after 9 that still use my ip address.

Strange
Sorry guys
Steven

Tom Carroll

Re: I think I've been hacked!
« Reply #4 on: May 16, 2003, 02:11:01 PM »
Craig, I just used the "last" command and it shows a "public" user who logged in through the ftp daemon.  Do you know what this "public" user is?

Would be an anonymous ftp session?

Thanks!

Tom

Terry Brummell

Re: I think I've been hacked!
« Reply #5 on: May 16, 2003, 03:45:10 PM »
Log in via FTP as an anonymous user and find out for yourself.  I just did it and yes, that connection shows up as public.

Terry