Thanks for the replys guys....

The IP could be spoofed... possible.

I was thinking of reporting it to the ISP.

I'm certainly not gonna spend a whole lot of time chasing anyone down.

As for damages..... I'd estimate it lower the 5k for sure.

Yves


On 3/2/07, Heald, Timothy J <[EMAIL PROTECTED]> wrote:
>
> What was the monetary value of the damage done?  If it wasn't over 5000
> (I think) the feds won't look at it.  Other options include contacting
> the company that owns the IP address, contacting the host government, or
> do nothing at all.  For your own time, money, and sanity I suggest you
> whipe the box and don't report it.
>
> Figure out how the malicious user gained access, then patch or repair
> whatever the fault was, then forget about it.
>
> --
> Timothy Heald
> Senior Developer/Architect
> HR/EX/SDD, SA-1, H808F
> Desk: 202-663-2752
> Fax: 202-261-8299
> Cell: 703-300-3911
>
> -----Original Message-----
> From: Yves Arsenault [mailto:[EMAIL PROTECTED]
> Sent: Friday, March 02, 2007 12:56 PM
> To: CF-Community
> Subject: Server has been hacked: Question
>
> Hey there!
>
> (Question way at the box.... context follows)
>
> I had quite a time these last couple of days.
>
> Yesterday morning, I discovered that one of my employer's linux servers
> was
> down... tried a few things to get some services up and running... but,
> misteriously I could no longer log in. (an old Linux Mandrake 10
> server...)
>
> So, I decided to reboot.
>
> After rebooting, I noticed that a couple of errors presented
> themselves....
>
> An error stating that a file couldn't be found... I was unshure what
> this
> file was... and I later found out.
>
> After that error, the "logger" service crashed. Weird.
>
> Anyways, after trying several things to log in without success... . I
> rebooted the box again using Knoppix on CD to boot up...
>
> I then proceeded to hack my password file. I changed the password to
> blank
> (as soon as I logged in, I changed it).
> I then created the files that were missing.... these files were used by
> the
> logger service to write to log files.. when I tried checking my logs...
> they
> were all blank.
> I was puzzled.
>
> I then booted up, logged in and started checking the server out... I
> quickly
> noticed that MANY files had simply vanished....
> Apache that was running on this box was GONE! As was some of Webmin and
> other stuff....
>
> I suspected from the start that maybe this box had some unwelcomed
> visitor....
>
> This morning... I checked the logs again....
>
> And there was some evidence.
>
> In my auth.log file... I saw a user (who previously didn't exist on the
> box)
> log in from an external IP. (From Romania to be precise)
>
> A user was created on this box.....
>
> Anyways... this box doesn't have much on it.... a couple of small sites
> I'm
> gonna move over and a few emails.
>
> So.. it seems this person hacked this box, disabled my logging services
> to
> hide his trail and had fun deleting stuff...
>
> Now... my question:
> Since I have this user's IP address how do I or can I report this?
>
> Anyone had an experience like this??
>
> Thanks CFers....
>
> --
> Yves Arsenault
>
> "Love is the only force capable of transforming an enemy into a friend".
> --Martin Luther King, Jr.
>
>
>
>
> 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~|
Macromedia ColdFusion MX7
Upgrade to MX7 & experience time-saving features, more productivity.
http://www.adobe.com/products/coldfusion

Archive: 
http://www.houseoffusion.com/groups/CF-Community/message.cfm/messageid:229329
Subscription: http://www.houseoffusion.com/groups/CF-Community/subscribe.cfm
Unsubscribe: http://www.houseoffusion.com/cf_lists/unsubscribe.cfm?user=89.70.5

Reply via email to