[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: Server Hacked



I doubt it. What services were/are you running? Did you use grsecurity or SELinux?

Brian C wrote:

My Debian server has been hacked. Every web page I hosted now reads:

"XTech Inc Was Here :D"
XTech Inc we are: Status-x & PABLIN77
uid=0(XTech Inc) gid=0(XTech Inc) groups=0(XTech Inc)
Pablin77: MARY TE AMO!!!!!!

Powered by XTech Inc / PABLIN77
Made in ARGENTINA - pablin_77@xxxxxxxxxxxxx

I run Debian-testing and generally stay on top of updates. I do run a
few too many services on that server though. I wonder if my recent
addition of making it a tor server is what brought my humble server to
these jerks attention? I've little experience with recovering from this,
so any advice on what steps to take from here, what log files are
relevant, etc. would be greatly appreciated.

Brian