Go Back   HowtoForge Forums | HowtoForge - Linux Howtos and Tutorials > Linux Forums > Kernel Questions

Do you like HowtoForge? Please consider supporting us by becoming a subscriber.
Reply
 
Thread Tools Display Modes
  #1  
Old 9th August 2008, 10:50
Hellbound Hellbound is offline
Senior Member
 
Join Date: Sep 2005
Posts: 116
Thanks: 4
Thanked 1 Time in 1 Post
Default urgent problem (server hacked), result: "segmentation fault"

Hi guys,

I've had a server hacked on my network running on CentOS (trixbox).

the root password was changed by intruder. so I tried to reboot using single mode on grub, however the disk was on READONLY and couldn't write passwd file.

So I reboot using trixbox CD and linux rescue option, and I managed to restore the password. but when I do mount -o remount,rw / it gives "SEGMENTATION FAULT"
when I do ifconfig i get the same thing and the eth0 comes up with "promiscuous mode" error which is another odd thing.

I tried to scan the kernel with chkrootkit and it was suspected on some of the things but did not give any information how to fix it.

I'm sorry to say this but I'm not a linux guru since I've been on Microsoft platform for a decade and now migrating to linux.

so if you know the solution to this please explain in basic steps that I can run.

Thanks a lot
Reply With Quote
Sponsored Links
  #2  
Old 10th August 2008, 13:05
falko falko is offline
Super Moderator
 
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 41,701
Thanks: 1,900
Thanked 2,747 Times in 2,578 Posts
Default

I strongly recommend to set up the system again from scratch - you can never know what else the hacker changed on the system. Maybe there are some other backdoors, etc.
__________________
Falko
--
Download the ISPConfig 3 Manual! | Check out the ISPConfig 3 Billing Module!

FB: http://www.facebook.com/howtoforge

nginx-Webhosting: Timme Hosting | Follow me on:
Reply With Quote
  #3  
Old 10th August 2008, 13:12
Hellbound Hellbound is offline
Senior Member
 
Join Date: Sep 2005
Posts: 116
Thanks: 4
Thanked 1 Time in 1 Post
Default

Hi

Thanks for the reply,
thats what i am intending to do. however I need to backup my databases from the latest state. and at this moment the mysql service doesn't run to fix it.


how can I do that?
thanks again
Reply With Quote
  #4  
Old 11th August 2008, 15:02
falko falko is offline
Super Moderator
 
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 41,701
Thanks: 1,900
Thanked 2,747 Times in 2,578 Posts
Default

You can back up the /var/lib/mysql directory and then copy over the database directories from this directory to the new server. Usually this does not cause any problems.
__________________
Falko
--
Download the ISPConfig 3 Manual! | Check out the ISPConfig 3 Billing Module!

FB: http://www.facebook.com/howtoforge

nginx-Webhosting: Timme Hosting | Follow me on:
Reply With Quote
  #5  
Old 11th August 2008, 15:35
Ben Ben is offline
Moderator
 
Join Date: Jul 2006
Posts: 1,029
Thanks: 7
Thanked 62 Times in 56 Posts
Default

Or booting the system with a liveCD like knoppix and copy the data to an usb drive or burn it to a cd.
Reply With Quote
  #6  
Old 11th August 2008, 18:51
Hellbound Hellbound is offline
Senior Member
 
Join Date: Sep 2005
Posts: 116
Thanks: 4
Thanked 1 Time in 1 Post
 
Default

Hi,

Thanks for your information. I will do as you mentioned about backup mysql folder, it is a good option

Thanks
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Email Clients cannot send mail iverson0881 Installation/Configuration 3 8th May 2008 09:34
cacti problem - graphs have huge gaps Chip Installation/Configuration 7 8th February 2008 00:24
Problem with keeping Apache alive bobeq Server Operation 3 29th November 2007 17:11
The Perfect Setup Suse 9.3 - Postfix problems new_bee05 HOWTO-Related Questions 20 25th November 2005 03:30
POP3 SMTP FTP problem arsu Installation/Configuration 1 11th November 2005 10:32


All times are GMT +2. The time now is 03:47.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2014, vBulletin Solutions, Inc.