Security

From: DJC (email_at_iqws.com)
Date: 04/27/05

  • Next message: Peer Hebing: "Re: Security"
    Date: Wed, 27 Apr 2005 10:24:21 +0100
    
    

    I have had a recent experience of someone compromising my system.
    I can see from the logs that somehow they logged in via SSH as an unkown
    user!? and then created a new root user
    >From this they have tried to scam people on ebay by using fake email
    addresses through my domain
    within 4 hours of this starting i have stopped it - basically by taking it
    down fully
    before i rebuild i wanted to know if anyone could suggest a way of stopping
    this in future
    my firewall was only open on ports 22,25,80 and 143

    TIA


  • Next message: Peer Hebing: "Re: Security"

    Relevant Pages

    • Re: Security
      ... > 2) services running ... > DJC wrote: ... and then created a new root user ... And if possible SSH Version- wasn't there a remote exploit a few years ...
      (linux.redhat)
    • Re: SSH Problem on Solaris 9
      ... I have a fresh install of Solaris9 and have enabled the root user to login using ssh. ... My problem is if I change the root user's shell from sh to bash, ... like to use the bash shell when using ssh. ...
      (comp.unix.solaris)
    • SSH Daemon Help
      ... I am having a issue with SSH daemons that won't release/remove from the ... system after ssh users logged off the system especially root user. ...
      (SunManagers)
    • Re: SSH Problem on Solaris 9
      ... I have a fresh install of Solaris9 and have enabled the root user to login ... I'm denied login using ssh unless I change it back to sh. ... we use tcsh, and tcsh is in /etc/shells here. ...
      (comp.unix.solaris)
    • Re: ssh2 login with public key - not working
      ... auth.log on box1 only prints a line when it accepts a public key. ... There are no auth failures because the problem occurs when ssh tries to determine the type of the authentication. ... Do you have any idea why the recreation of the user solved the problem? ... And how it is possible that using exactly the same ssh config, the root user cannot login with a public key? ...
      (freebsd-questions)