Answer the question
In order to leave comments, you need to log in
How to fix a server hack?
Good afternoon, please tell me, there is a server on ubuntu 14.04 that has been receiving azuza several times a month and is being turned off. Worth iptable (white list) and fail2ban. Bash files appear in the tmp folder that brute force other servers via ssh. What can be done to correct this situation?
Answer the question
In order to leave comments, you need to log in
Any hack is eliminated in three stages:
1) Turn off the affected computer.
2) Loading from a reliable medium (flash drive) and studying the logs, searching for traces of hacking, finding out the method of defeat and identifying the vulnerability that allowed the attack, as well as the changes made by the hacker.
3) Reinstalling the entire system, optionally - restoring content from a backup, closing detected holes (for example, updating plugins for wordpress if you have its engine), changing all passwords, starting the server.
You can do without reinstallation if you are sure that the cracker could not get root rights and install rootkits. But it is better to play it safe right away than to find out two days later that everything was in vain.
Сильно вероятно что "ломают" через http т.к. не настроены права нормально на доступы или используете свои самописные странички.
if you access the server from static ips, restrict access to ssh only from these ips. close access to ssh for root. Monitor top for suspicious files (I got fshquyrwb something like this).
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question