That's probably a good idea.

I'll be meeting with my boss early in the week... we'll see what comes of
it.

To update you.... yesterday, I had other things to tend to and couldn't
reinstall everything last night.

So, I deleted this dude's user account and disabled a couple of things,
leaving only the main services this box was running.... I thought about it
alot last night...

This morning, I came in and checked the auth.log file.... the bugger tried
to log in and couldn't...

Now.. it's decision time for me as to how to proceed at the moment.

Thanks,

Yves


On 3/2/07, Cameron Childress <[EMAIL PROTECTED]> wrote:
>
> one more suggestion... this may be a good opportunity to get your
> employer to pay for a security audit and threat analysis.  most
> eployers won't even consider it till it's too late, and I would say
> it's that time for you right now.
>
> would be a great learning opportunity for you and it would benefit
> your employer as well!
>
> -cameron
>
> On 3/2/07, Yves Arsenault <[EMAIL PROTECTED]> wrote:
> > Thanks for the replys guys....
> >
> > The IP could be spoofed... possible.
> >
> > I was thinking of reporting it to the ISP.
> >
> > I'm certainly not gonna spend a whole lot of time chasing anyone down.
> >
> > As for damages..... I'd estimate it lower the 5k for sure.
> >
> > Yves
> >
> >
> > On 3/2/07, Heald, Timothy J <[EMAIL PROTECTED]> wrote:
> > >
> > > What was the monetary value of the damage done?  If it wasn't over
> 5000
> > > (I think) the feds won't look at it.  Other options include contacting
> > > the company that owns the IP address, contacting the host government,
> or
> > > do nothing at all.  For your own time, money, and sanity I suggest you
> > > whipe the box and don't report it.
> > >
> > > Figure out how the malicious user gained access, then patch or repair
> > > whatever the fault was, then forget about it.
> > >
> > > --
> > > Timothy Heald
> > > Senior Developer/Architect
> > > HR/EX/SDD, SA-1, H808F
> > > Desk: 202-663-2752
> > > Fax: 202-261-8299
> > > Cell: 703-300-3911
> > >
> > > -----Original Message-----
> > > From: Yves Arsenault [mailto:[EMAIL PROTECTED]
> > > Sent: Friday, March 02, 2007 12:56 PM
> > > To: CF-Community
> > > Subject: Server has been hacked: Question
> > >
> > > Hey there!
> > >
> > > (Question way at the box.... context follows)
> > >
> > > I had quite a time these last couple of days.
> > >
> > > Yesterday morning, I discovered that one of my employer's linux
> servers
> > > was
> > > down... tried a few things to get some services up and running... but,
> > > misteriously I could no longer log in. (an old Linux Mandrake 10
> > > server...)
> > >
> > > So, I decided to reboot.
> > >
> > > After rebooting, I noticed that a couple of errors presented
> > > themselves....
> > >
> > > An error stating that a file couldn't be found... I was unshure what
> > > this
> > > file was... and I later found out.
> > >
> > > After that error, the "logger" service crashed. Weird.
> > >
> > > Anyways, after trying several things to log in without success... . I
> > > rebooted the box again using Knoppix on CD to boot up...
> > >
> > > I then proceeded to hack my password file. I changed the password to
> > > blank
> > > (as soon as I logged in, I changed it).
> > > I then created the files that were missing.... these files were used
> by
> > > the
> > > logger service to write to log files.. when I tried checking my
> logs...
> > > they
> > > were all blank.
> > > I was puzzled.
> > >
> > > I then booted up, logged in and started checking the server out... I
> > > quickly
> > > noticed that MANY files had simply vanished....
> > > Apache that was running on this box was GONE! As was some of Webmin
> and
> > > other stuff....
> > >
> > > I suspected from the start that maybe this box had some unwelcomed
> > > visitor....
> > >
> > > This morning... I checked the logs again....
> > >
> > > And there was some evidence.
> > >
> > > In my auth.log file... I saw a user (who previously didn't exist on
> the
> > > box)
> > > log in from an external IP. (From Romania to be precise)
> > >
> > > A user was created on this box.....
> > >
> > > Anyways... this box doesn't have much on it.... a couple of small
> sites
> > > I'm
> > > gonna move over and a few emails.
> > >
> > > So.. it seems this person hacked this box, disabled my logging
> services
> > > to
> > > hide his trail and had fun deleting stuff...
> > >
> > > Now... my question:
> > > Since I have this user's IP address how do I or can I report this?
> > >
> > > Anyone had an experience like this??
> > >
> > > Thanks CFers....
> > >
> > > --
> > > Yves Arsenault
> > >
> > > "Love is the only force capable of transforming an enemy into a
> friend".
> > > --Martin Luther King, Jr.
> > >
> > >
> > >
> > >
> > >
> >
> >
>
> 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~|
Macromedia ColdFusion MX7
Upgrade to MX7 & experience time-saving features, more productivity.
http://www.adobe.com/products/coldfusion

Archive: 
http://www.houseoffusion.com/groups/CF-Community/message.cfm/messageid:229375
Subscription: http://www.houseoffusion.com/groups/CF-Community/subscribe.cfm
Unsubscribe: 
http://www.houseoffusion.com/cf_lists/unsubscribe.cfm?user=11502.10531.5

Reply via email to