Add to Favorites
Hosting Discussion
 

forgot password?


Reply


Old
  Post #1 (permalink)   11-06-2005, 08:29 AM
HD Newbie
 
Join Date: Sep 2005
Posts: 20

Status: Gineey is offline
Hey it is not common; but anybody can face- What you do if your server got hacked ..?
__________________
JodoHost.com
Windows 2003 | Cold Fusion MX | SQL Server | ASP.NET and Oracle Servers Multiplatform Reseller Plans (Windows/Linux/VPS)| 24x7x365 Live Support, Anonymous Reseller End-Users Support Live Chat
 
 
 


Old
  Post #2 (permalink)   11-07-2005, 07:34 PM
HD Amateur
 
Join Date: Nov 2005
Posts: 89

Status: Dediwebhost.com is offline
What kind of box is it? A co-location box or a dedicated server that you leased from a provider?

Is it a fully managed server of unmanaged server?
__________________
Dedicated servers for a great price. Resellers are welcome.
www.dediwebhost.com
 
 
 


Old
  Post #3 (permalink)   11-08-2005, 04:15 AM
HD Newbie
 
Join Date: Sep 2005
Posts: 20

Status: Gineey is offline
What is the differeance if it is co-location box or a dedicated server ? is that matter in Server Hacking Case ??
__________________
JodoHost.com
Windows 2003 | Cold Fusion MX | SQL Server | ASP.NET and Oracle Servers Multiplatform Reseller Plans (Windows/Linux/VPS)| 24x7x365 Live Support, Anonymous Reseller End-Users Support Live Chat
 
 
 


Old
  Post #4 (permalink)   11-08-2005, 08:15 AM
HD Newbie
 
Join Date: Apr 2005
Posts: 6

Status: rootsupport is offline
First change the root password, and get your security administrator to check the complete server and remove all vulnerable scripts, delete unwanted users if they have been created etc...
__________________
RootSupport.Com - Solutions That Fit On The First Try
::::: AIM: linuxengineers ::::: MSN: msn@rootsupport.com :::::
24/7 Technical Support - Linux and Windows Servers
 
 
 


Old
  Post #5 (permalink)   09-21-2007, 03:55 AM
HD Newbie
 
Join Date: Sep 2007
Posts: 27

Status: sparkstation is offline
Reinstall get a firewall and monitoring software
__________________
<<MOD NOTE: See rules for signature setup.>>
 
 
 


Old
  Post #6 (permalink)   10-29-2007, 12:59 PM
HD Amateur
 
Join Date: Sep 2007
Posts: 51

Status: indyamail is offline
Hire a Serveradmin who can take care of the same for you . There is no reason to waste time trying to learn and play around (unless youre sites can risk that). Get a server admin or choose a host that provides some managed solutions.

I'm sure things will work out just fine
__________________
IndyaMail.Com - Proud to Be Indian, Proud to Be Worldwide.
IndyaMail VPS, Resellers and Shared Hosting
IndyaMail Email Service
 
 
 


Old
  Post #7 (permalink)   01-01-2008, 07:03 PM
HD Newbie
 
Join Date: Nov 2007
Posts: 27

Status: dbihosting is offline
Hopefully you have a backup of your data. Wipe the box and move the accounts over to another server.
__________________
DBI Hosting - Shared - Dedicated - VPS - Managed
 
 
 


Old
  Post #8 (permalink)   01-02-2008, 10:12 AM
HD Community Advisor
 
Join Date: Sep 2005
Location: England
Posts: 678

Status: Matthew is offline
I supported mainly Windows servers. When ever there was a breech reported by a client it was always some old script that they had installed where a "hacker" or kiddie hacker basically uploaded a file browser and replaced the users index file. Only the account was effected and the server was not attacked.

In the one case where an actual server breech happened it was related to a vulnerability in the mail software where no fix was available at the time of the hack. For that case a complete reinstal and restore of data was done (minus the bad software).
__________________
Matthew
 
 
 


Old
  Post #9 (permalink)   01-31-2008, 10:25 AM
HD Newbie
 
Join Date: Nov 2007
Posts: 43

Status: vpsville is offline
It depends on the hack. Most hacks occur because of insecure passwords or default security settings. If you are hacked, look there first.

A firewall does nothing in these cases but everyone seems to think they are the bee's knee's.

Word of advice, secure the system fully and THEN install a firewall. Don't rely on a firewall and don't expect it to secure a webserver or mailserver. Those services require open ports anyway.
__________________
VPSVille
Canadian VPS Hosting
www.vpsville.ca
 
 
 


Old
  Post #10 (permalink)   01-31-2008, 09:47 PM
HD Amateur
 
Join Date: Jan 2008
Location: In a cave
Posts: 143

Status: shockym is offline
Quote:
Originally Posted by rootsupport View Post
First change the root password, and get your security administrator to check the complete server and remove all vulnerable scripts, delete unwanted users if they have been created etc...
I would go with:
- make sure their not still in the box to start with

- stop all processes you have no idea what they are
(esp. if they are some type of cron job running that you did not auth.)

- change passwords
(if its a hosting box, start changing all clients pwds too)

- continue to work to fix the expolitation point and fix

- send someone out for coffee and/or Mt. Dew........it could very well be an all nighter you pull if you are doing this alone.
 
 
 
Reply

Thread Tools

New Post New Post   Old Post Old Post
Posting Rules:
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On