What was the monetary value of the damage done? If it wasn't over 5000 (I think) the feds won't look at it. Other options include contacting the company that owns the IP address, contacting the host government, or do nothing at all. For your own time, money, and sanity I suggest you whipe the box and don't report it.
Figure out how the malicious user gained access, then patch or repair whatever the fault was, then forget about it. -- Timothy Heald Senior Developer/Architect HR/EX/SDD, SA-1, H808F Desk: 202-663-2752 Fax: 202-261-8299 Cell: 703-300-3911 -----Original Message----- From: Yves Arsenault [mailto:[EMAIL PROTECTED] Sent: Friday, March 02, 2007 12:56 PM To: CF-Community Subject: Server has been hacked: Question Hey there! (Question way at the box.... context follows) I had quite a time these last couple of days. Yesterday morning, I discovered that one of my employer's linux servers was down... tried a few things to get some services up and running... but, misteriously I could no longer log in. (an old Linux Mandrake 10 server...) So, I decided to reboot. After rebooting, I noticed that a couple of errors presented themselves.... An error stating that a file couldn't be found... I was unshure what this file was... and I later found out. After that error, the "logger" service crashed. Weird. Anyways, after trying several things to log in without success... . I rebooted the box again using Knoppix on CD to boot up... I then proceeded to hack my password file. I changed the password to blank (as soon as I logged in, I changed it). I then created the files that were missing.... these files were used by the logger service to write to log files.. when I tried checking my logs... they were all blank. I was puzzled. I then booted up, logged in and started checking the server out... I quickly noticed that MANY files had simply vanished.... Apache that was running on this box was GONE! As was some of Webmin and other stuff.... I suspected from the start that maybe this box had some unwelcomed visitor.... This morning... I checked the logs again.... And there was some evidence. In my auth.log file... I saw a user (who previously didn't exist on the box) log in from an external IP. (From Romania to be precise) A user was created on this box..... Anyways... this box doesn't have much on it.... a couple of small sites I'm gonna move over and a few emails. So.. it seems this person hacked this box, disabled my logging services to hide his trail and had fun deleting stuff... Now... my question: Since I have this user's IP address how do I or can I report this? Anyone had an experience like this?? Thanks CFers.... -- Yves Arsenault "Love is the only force capable of transforming an enemy into a friend". --Martin Luther King, Jr. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~| ColdFusion MX7 by AdobeĀ® Dyncamically transform webcontent into Adobe PDF with new ColdFusion MX7. Free Trial. http://www.adobe.com/products/coldfusion Archive: http://www.houseoffusion.com/groups/CF-Community/message.cfm/messageid:229327 Subscription: http://www.houseoffusion.com/groups/CF-Community/subscribe.cfm Unsubscribe: http://www.houseoffusion.com/cf_lists/unsubscribe.cfm?user=89.70.5
