GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   need FreeBSD help - servers been hacked! (https://gfy.com/showthread.php?t=487037)

rickdu 06-30-2005 11:52 AM

need FreeBSD help - servers been hacked!
 
tech support @ my provider can't help at all.. i won't even go into how much i hate them.. what I do know is it's sending mass spam emails from somewhere that I can't locate so far.. im not sure what to do now, so any advice is appreciated. :helpme

ICQ: 63-149-919

rickdu 06-30-2005 12:49 PM

if anyone is a web host and can help with this problem, i'll make the switch to your service next week. I'm still paid for 3 weeks with these people, but I'll switch next week if you can help

lawked 06-30-2005 01:03 PM

You're saying your machine is spamming and you don't know why?

Open 2 sessions:

netstat -w1

Monitors how much your server is sending.

netstat -an in another session... shows the network activety.

sockstat - shows ports opened by software.

It's probably related to a php script as FreeBSD is tight.

prodiac 06-30-2005 01:06 PM

Quote:

Originally Posted by rick702
tech support @ my provider can't help at all.. i won't even go into how much i hate them.. what I do know is it's sending mass spam emails from somewhere that I can't locate so far.. im not sure what to do now, so any advice is appreciated. :helpme

ICQ: 63-149-919

ICQ'd you

rickdu 06-30-2005 01:07 PM

Quote:

Originally Posted by lawked
It's probably related to a php script as FreeBSD is tight.

im hoping so.. i upgraded php from 4.3.6 to 4.3.11 and i HOPE that will help.. im not seeing anything being sent right now

FireFoz 06-30-2005 01:31 PM

hey hit me up icq 6981021 i might be able to help you out ab it

marketsmart 06-30-2005 01:58 PM

You need to rebuild the box, unless you just have an open relay. My guess would be an open port that they gained access or hacked the box and created a relay. In the future hire someone to lockdown your machine. Close all unnecessary ports, make sure all directories have the right permissions and only allow specific IP's to come in remote for admin.

Although anything (like exploits or a simple admin mistake) can leave you open, most hackers are looking for easy access (they have plenty of other choices) and will not spend time on a pretty secured box.

My two cents....

webair 06-30-2005 02:18 PM

icq'd contact me


All times are GMT -7. The time now is 08:33 PM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123