Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

My suggestions: If your server has confidential/money related info. take down the server. If not , wait because even if you bring up new server. How do you know , he won't crack it again?

- Check your /var/log/messages & audit.log & ssh/d.log

- Check lastb & last command outputs

- Take dump of network connections. (netstat)

- find out his 'tty' and spy on him! with something like sysdig or using strace (http://serverfault.com/a/423666)

Most importantly do these after turning off bash_history.So that attacker won't see you are gather information.

I assume you are running Linux server.



> - Check lastb & last command outputs

I wasn't aware of lastb, thanks.

I'm impressed that my home server has logged over 650,000 failed logins since 1 July, and a couple of machines I administer in a university over 300,000 each. That's every three-four seconds for the home server.

That's quite a lot of bandwidth, worldwide.


Some kind of auto-bot is attacking, fine-tune the firewall settings :)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: