|
The last time my server was hacked, I just shut down webserver and found the hacker log files and deleted the file that was uploaded. I then patched or updated all of my software and changed root password and other passwords. It solved the problem for me and I never tried to track down the hacker. They usually leave a log file or irc log for you to look at.
If your server provider finds out that your system was compromised, some have mandatory policies to re-install system image which will wipe out everything.
|