Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 06-30-2005, 11:52 AM   #1
rickdu
Confirmed User
 
Industry Role:
Join Date: Mar 2005
Location: Los Angeles
Posts: 239
need FreeBSD help - servers been hacked!

tech support @ my provider can't help at all.. i won't even go into how much i hate them.. what I do know is it's sending mass spam emails from somewhere that I can't locate so far.. im not sure what to do now, so any advice is appreciated.

ICQ: 63-149-919
rickdu is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-30-2005, 12:49 PM   #2
rickdu
Confirmed User
 
Industry Role:
Join Date: Mar 2005
Location: Los Angeles
Posts: 239
if anyone is a web host and can help with this problem, i'll make the switch to your service next week. I'm still paid for 3 weeks with these people, but I'll switch next week if you can help
rickdu is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-30-2005, 01:03 PM   #3
lawked
Confirmed User
 
Join Date: Apr 2003
Location: Canada
Posts: 354
You're saying your machine is spamming and you don't know why?

Open 2 sessions:

netstat -w1

Monitors how much your server is sending.

netstat -an in another session... shows the network activety.

sockstat - shows ports opened by software.

It's probably related to a php script as FreeBSD is tight.
lawked is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-30-2005, 01:06 PM   #4
prodiac
Confirmed User
 
Industry Role:
Join Date: Sep 2003
Location: amerinoc.com
Posts: 419
Quote:
Originally Posted by rick702
tech support @ my provider can't help at all.. i won't even go into how much i hate them.. what I do know is it's sending mass spam emails from somewhere that I can't locate so far.. im not sure what to do now, so any advice is appreciated.

ICQ: 63-149-919
ICQ'd you
prodiac is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-30-2005, 01:07 PM   #5
rickdu
Confirmed User
 
Industry Role:
Join Date: Mar 2005
Location: Los Angeles
Posts: 239
Quote:
Originally Posted by lawked
It's probably related to a php script as FreeBSD is tight.
im hoping so.. i upgraded php from 4.3.6 to 4.3.11 and i HOPE that will help.. im not seeing anything being sent right now
rickdu is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-30-2005, 01:31 PM   #6
FireFoz
Confirmed User
 
Join Date: Apr 2002
Posts: 480
hey hit me up icq 6981021 i might be able to help you out ab it
__________________
FireFoz is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-30-2005, 01:58 PM   #7
marketsmart
HOMICIDAL TROLL KILLER
 
Industry Role:
Join Date: Dec 2004
Location: Sunnybrook Institution for the Criminally Insane
Posts: 20,419
You need to rebuild the box, unless you just have an open relay. My guess would be an open port that they gained access or hacked the box and created a relay. In the future hire someone to lockdown your machine. Close all unnecessary ports, make sure all directories have the right permissions and only allow specific IP's to come in remote for admin.

Although anything (like exploits or a simple admin mistake) can leave you open, most hackers are looking for easy access (they have plenty of other choices) and will not spend time on a pretty secured box.

My two cents....
marketsmart is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-30-2005, 02:18 PM   #8
webair
Confirmed User
 
webair's Avatar
 
Industry Role:
Join Date: Feb 2002
Location: NYC, NY
Posts: 8,531
icq'd contact me
webair is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.