|
|
|
||||
|
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() |
|
|||||||
| Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
|
Thread Tools |
|
|
#1 |
|
So Fucking Banned
Join Date: Feb 2005
Posts: 3,134
|
Looking for FreeBSD Help
Long story short. It appears someone compromised my server and replaced some vital command files ( ls netstat ps du find killall pstree top vdir whereis) to Linux versions.
Does anyone have FreeBSD copies of these files they could send me? I am hoping to replace these files and begin some sort of investigation and not have to do a OS reload.. Any other possible suggestions? Thanks |
|
|
|
|
|
#2 |
|
So Fucking Banned
Join Date: Apr 2007
Posts: 325
|
If the server is compromised then you don't have any other option except to format the drive and reinstall, hope you have good backups. You can't trust anything your server tells you, there could be backdoors anywhere.
|
|
|
|
|
|
#3 |
|
So Fucking Banned
Join Date: Feb 2005
Posts: 3,134
|
I will take my chances.. Awful hard to start anywhere when I cant even see what proccess are running
|
|
|
|
|
|
#4 |
|
Confirmed User
Join Date: Jun 2007
Location: Quebec City, Quebec
Posts: 133
|
hey i can help you out if you want... contact me on ICQ.
__________________
chesterbanksphp [.at.] gmail.com
icq: 350 656 495 |
|
|
|
|
|
#5 |
|
So Fucking Banned
Join Date: Apr 2007
Posts: 325
|
that's why hackers install their own versions of ps, lsof etc... So they can hide the haxor processes they have running.
|
|
|
|
|
|
#6 | |
|
Confirmed User
Join Date: Jan 2005
Posts: 2,270
|
Quote:
__________________
E-mail marketing - Automation Scripting - IP Space AIM: splitjoelp ICQ: 254759453 skype - splitjoelp 702-941-6465 |
|
|
|
|
|
|
#7 |
|
Too lazy to set a custom title
Join Date: Jun 2004
Location: Brasil
Posts: 15,778
|
format everything...and re install the OS...
__________________
Do you need cheap, fast and reliable porn website hosting? Host Head is the way to go!! Asian Gay Special | Live on MSN - Live Webcam Chat | Live Adult Webcam Performances | MY SWEET BLACKS LIVE ON CAM Pukka Tranny | Tattooed Shemales | She's A He | Menu Porno | Porn Performances | All Chubby MY ICQ# 169833797 |
|
|
|
|
|
#8 |
|
Too lazy to set a custom title
Join Date: Mar 2002
Location: Australia
Posts: 17,393
|
Here's another hand for reinstalling from scratch. Restore data, not executables.
|
|
|
|
|
|
#9 |
|
So Fucking Banned
Join Date: Feb 2005
Posts: 3,134
|
Thanks for the replies.
I agree with an OS reload. But I would like to at least try and look into the issue before I go through with a re-install. Without the proper tools I cant see ANYTHING |
|
|
|
|
|
#10 |
|
Too lazy to set a custom title
Join Date: Mar 2002
Location: Australia
Posts: 17,393
|
You need more than people to send you replacement files, get expert help so you can be sure it's not going to happen again.
|
|
|
|
|
|
#11 |
|
Confirmed User
Industry Role:
Join Date: Jun 2003
Location: My High Horse
Posts: 6,334
|
I was a UNIX admin for NASA Im gonna tell you like it is man.
FORMAT and reinstall PERIOD you are fucked if you dont and afterwards make sure your security is audited by a real UNIX admin
__________________
Mike South It's No wonder I took up drugs and alcohol, it's the only way I could dumb myself down enough to cope with the morons in this biz. |
|
|
|
|
|
#12 |
|
Too lazy to set a custom title
Join Date: Mar 2002
Location: Australia
Posts: 17,393
|
Better to do it the other way around so it doesn't happen again. Security guy looks at the server now, figures out what went wrong, reinstalls and applies necessary patches.
|
|
|
|
|
|
#13 |
|
Spread The Pink!
Join Date: Nov 2004
Location: pinktown!
Posts: 8,229
|
total reinstall. it's the only way to be sure if your entire server is compromised.
![]()
__________________
tassy*PINK * ICQ ~ 318*097*066 * |
|
|
|
|
|
#14 |
|
Confirmed User
Join Date: Apr 2002
Location: /root/
Posts: 4,997
|
Your server must've been really old because its not such a piece of cake
to get root on a freebsd server. You probably had some 4.x, I would reinstall with a newer version of the os and have the server locked down by someone who knows what he's doing. |
|
|
|