GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   My server has been compromised... (https://gfy.com/showthread.php?t=600688)

GFED 04-21-2006 11:11 AM

My server has been compromised...
 
and i'm receiving a thousand return mails everyday... :/

IMPORTANT: Do not ignore this email.
This message is to inform you that the rpm
package fileutils did not match the expected checksum. This could mean that
your system was compromised (OwN3D). The offending files have been removed
and replaced with the OS default. To be safe you should verify that your
system has not be compromised.

:(

TheSenator 04-21-2006 11:12 AM

That sucks... Do you have a sys admin? Or do you do it yourself?

Tom_PM 04-21-2006 11:14 AM

Are you really banned? wtf, lol..

That does suck, but the email really said (OwN3D)??? thats weird.

GFED 04-21-2006 02:12 PM

it's a self managed server at rack shack... yeah thats what the email said... lol... :)

GFED 04-21-2006 02:13 PM

no, i'm not really banned... :p

Downtime 04-21-2006 02:15 PM

that sucks man, hope it gets resolved soon

Manowar 04-21-2006 02:23 PM

that sucks dude

split_joel 04-21-2006 02:43 PM

Quote:

Originally Posted by GFED
and i'm receiving a thousand return mails everyday... :/

IMPORTANT: Do not ignore this email.
This message is to inform you that the rpm
package fileutils did not match the expected checksum. This could mean that
your system was compromised (OwN3D). The offending files have been removed
and replaced with the OS default. To be safe you should verify that your
system has not be compromised.

:(

what are you paying over there? We will secure and manage your server for you so this will never happen again. Not trying to steal you from anyone but that should never happen.

split_joel 04-21-2006 02:50 PM

also i doubt that package did any harm to your system you can read about it here.

http://rpm.pbone.net/index.php3/stat....i586.rpm.html

fris 04-21-2006 02:54 PM

Quote:

Originally Posted by split_joel
what are you paying over there? We will secure and manage your server for you so this will never happen again. Not trying to steal you from anyone but that should never happen.

can you beat 170$ a month for 10mbps unmetered?

or 265$ a month for 20mbps?

GFED 04-22-2006 01:38 AM

all my logs have the intrusion coming from one ip address... can someone check it out for me? how do i block it?

81.10.192.58

GFED 04-22-2006 01:39 AM

Hidden Pid detected! [pid 17811]
hidden from ps: [yes]
binary location: [/tmp/sh-B1LCCY4ARMS (deleted)]

Hidden Pid detected! [pid 17816]
hidden from ps: [yes]
binary location: [/sbin/ttymon]

GFED 04-23-2006 05:46 AM

bump....

wyldblyss 04-23-2006 05:51 AM

Quote:

Originally Posted by GFED
it's a self managed server at rack shack... yeah thats what the email said... lol... :)

I know you must be going nuts now trying to get things in order and I don't mean to laugh...but the email saying you were OwN3D is too much! hehe

Juicy D. Links 04-23-2006 05:58 AM

GFED i can find the troll for you , cock slapp him and break his hands so he cant type lmk

GFED 04-25-2006 11:23 PM

Quote:

Originally Posted by Juicy D. Links
GFED i can find the troll for you , cock slapp him and break his hands so he cant type lmk

yes please cockslap him for me... :p

GFED 04-27-2006 01:40 AM

i keep getting the emails... grrr...

HDTV Bucks 04-27-2006 01:47 AM

I'm been getting spammed a few hundred times a day by some really stupid "Your Message Could Not Be Delivered" type thing, so I feel your pain. :helpme

ServerGenius 04-27-2006 01:49 AM

See Sig :winkwink:

Sven-David 04-27-2006 04:00 AM

bump that

GFED 04-27-2006 08:09 AM

fuck... rackshack cant fix it... they told me to back up all my shit and order a reimage... :(

MrQ 04-27-2006 08:12 AM

Quote:

Originally Posted by GFED
and i'm receiving a thousand return mails everyday... :/

IMPORTANT: Do not ignore this email.
This message is to inform you that the rpm
package fileutils did not match the expected checksum. This could mean that
your system was compromised (OwN3D). The offending files have been removed
and replaced with the OS default. To be safe you should verify that your
system has not be compromised.

:(


You ought to look into getting a sysadmin

marketsmart 04-27-2006 08:12 AM

Quote:

Originally Posted by GFED
all my logs have the intrusion coming from one ip address... can someone check it out for me? how do i block it?

81.10.192.58

vi /etc/hosts.deny

minusonebit 04-27-2006 08:25 AM

First of all, your system HAS been compromised and the system utilities probably have been patched, that is, modified so that the hacker can get back in or whatever.

When the OS has been molested like that, the only thing you can do is backup everything, format and start over. Even if you lock the intruder out, you cannot trust the integrity of the OS anymore.

Second, you need to get a sysadmin. Go over to WebHostingTalk.com and post for a sysadmin. You'll get plenty of knowledgeable responses from people who will work for next to nothing via PayPal.

Do you use cPanel, by any chance? I had this happen to a cPanel server about a year ago, it was the biggest fucking headache ever. I eventually laid the blame on a hole in phpBB and/or cPanel.

jacked 04-27-2006 08:32 AM

thats pretty fuckin gay

ffmihai 04-27-2006 08:50 AM

oh shit hire someone to manage the problem!

micker 04-27-2006 09:05 AM

Quote:

Originally Posted by GFED
and i'm receiving a thousand return mails everyday... :/

IMPORTANT: Do not ignore this email.
This message is to inform you that the rpm
package fileutils did not match the expected checksum. This could mean that
your system was compromised (OwN3D). The offending files have been removed
and replaced with the OS default. To be safe you should verify that your
system has not be compromised.

:(


I think someone is trying to mess with you. Is there more to that message you're getting? I've been working with unix systems a long time and never, have I ever seen an error message that used the word 'OwN3D'. Granted, I've never been a redhat guy, and for all I know thats an actual redhat error message.

I'm going to be gone most of the day, but if you're still having problems this evening, feel free to hit me up on icq 206-403-725.

Good luck with it!

darksoul 04-27-2006 09:11 AM

I guess you don't care too much about that server since 6 days are past and you didn't took care of it.

darksoul 04-27-2006 09:14 AM

Quote:

Originally Posted by micker
I've been working with unix systems a long time and never, have I ever seen an error message that used the word 'OwN3D'. Granted, I've never been a redhat guy, and for all I know thats an actual redhat error message.

that message is from a cpanel script and yea it really says OwN3D

GFED 04-27-2006 09:51 AM

Quote:

Originally Posted by darksoul
I guess you don't care too much about that server since 6 days are past and you didn't took care of it.

i'm working on it... :/


All times are GMT -7. The time now is 06:41 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123