Thanks for the replys guys.... The IP could be spoofed... possible.
I was thinking of reporting it to the ISP. I'm certainly not gonna spend a whole lot of time chasing anyone down. As for damages..... I'd estimate it lower the 5k for sure. Yves On 3/2/07, Heald, Timothy J <[EMAIL PROTECTED]> wrote: > > What was the monetary value of the damage done? If it wasn't over 5000 > (I think) the feds won't look at it. Other options include contacting > the company that owns the IP address, contacting the host government, or > do nothing at all. For your own time, money, and sanity I suggest you > whipe the box and don't report it. > > Figure out how the malicious user gained access, then patch or repair > whatever the fault was, then forget about it. > > -- > Timothy Heald > Senior Developer/Architect > HR/EX/SDD, SA-1, H808F > Desk: 202-663-2752 > Fax: 202-261-8299 > Cell: 703-300-3911 > > -----Original Message----- > From: Yves Arsenault [mailto:[EMAIL PROTECTED] > Sent: Friday, March 02, 2007 12:56 PM > To: CF-Community > Subject: Server has been hacked: Question > > Hey there! > > (Question way at the box.... context follows) > > I had quite a time these last couple of days. > > Yesterday morning, I discovered that one of my employer's linux servers > was > down... tried a few things to get some services up and running... but, > misteriously I could no longer log in. (an old Linux Mandrake 10 > server...) > > So, I decided to reboot. > > After rebooting, I noticed that a couple of errors presented > themselves.... > > An error stating that a file couldn't be found... I was unshure what > this > file was... and I later found out. > > After that error, the "logger" service crashed. Weird. > > Anyways, after trying several things to log in without success... . I > rebooted the box again using Knoppix on CD to boot up... > > I then proceeded to hack my password file. I changed the password to > blank > (as soon as I logged in, I changed it). > I then created the files that were missing.... these files were used by > the > logger service to write to log files.. when I tried checking my logs... > they > were all blank. > I was puzzled. > > I then booted up, logged in and started checking the server out... I > quickly > noticed that MANY files had simply vanished.... > Apache that was running on this box was GONE! As was some of Webmin and > other stuff.... > > I suspected from the start that maybe this box had some unwelcomed > visitor.... > > This morning... I checked the logs again.... > > And there was some evidence. > > In my auth.log file... I saw a user (who previously didn't exist on the > box) > log in from an external IP. (From Romania to be precise) > > A user was created on this box..... > > Anyways... this box doesn't have much on it.... a couple of small sites > I'm > gonna move over and a few emails. > > So.. it seems this person hacked this box, disabled my logging services > to > hide his trail and had fun deleting stuff... > > Now... my question: > Since I have this user's IP address how do I or can I report this? > > Anyone had an experience like this?? > > Thanks CFers.... > > -- > Yves Arsenault > > "Love is the only force capable of transforming an enemy into a friend". > --Martin Luther King, Jr. > > > > > ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~| Macromedia ColdFusion MX7 Upgrade to MX7 & experience time-saving features, more productivity. http://www.adobe.com/products/coldfusion Archive: http://www.houseoffusion.com/groups/CF-Community/message.cfm/messageid:229329 Subscription: http://www.houseoffusion.com/groups/CF-Community/subscribe.cfm Unsubscribe: http://www.houseoffusion.com/cf_lists/unsubscribe.cfm?user=89.70.5
