Linked Questions
578 questions linked to/from How do I deal with a compromised server?
27 votes
14 answers
5k views
HELP! Production DB was SQL INJECTED! [duplicate]
Possible Duplicate: My server's been hacked EMERGENCY Geeze, I'm desperate! A few hours ago our production DB was sql-injected. I know we have some big holes in the system... because we ...
12 votes
11 answers
2k views
Site hacked, looking for security advice [duplicate]
Possible Duplicate: My server's been hacked EMERGENCY Last weekend my company's site was hacked. They did the nicest thing of doing that on a Friday evening so we only noticed the attack on ...
12 votes
3 answers
71k views
How to find which script on my server is sending spam emails? [duplicate]
My server is sending the spam email and I am not able to find out which script is sending them. The emails were all from nobody@myhost so disabled from the cpanel that nobody should not be allowed ...
6 votes
6 answers
3k views
Attempted hack on VPS, how to protect in future, what were they trying to do? [duplicate]
UPDATE: They're still here. Help me stop or trap them! Hi SF'ers, I've just had someone hack one of my clients sites. They managed to get to change a file so that the checkout page on the site writes ...
5 votes
7 answers
853 views
Server was hacked. Now login wont accept 'root' as username comes up invalid [duplicate]
On Fedora, root is coming up invalid. WHat is solution?
8 votes
2 answers
6k views
Rootkit Revealer is failing to run, why? [duplicate]
On a user's laptop (Windows 7 x64), terrible performance led me to suspect a rootkit after ruling almost everything else out. I checked boot entries with Autoruns and ran a full scan with Malwarebytes,...
6 votes
5 answers
9k views
.htaccess being hacked repeatedly [duplicate]
About 4 or 5 days ago, a client came back to me saying that their site was being redirected to some other suspicious looking website from Google, Yahoo, etc., but it was working fine when the user ...
7 votes
1 answer
127k views
Ping request could not find host www.google.com. Please check the name and try a gain [duplicate]
I'm using Windows XP Professional Version 2002 Service Pack 3. I have issues with DNS (after affected by some malware). I cannot ping the sites, but I can browse using a web browser. I have tried the ...
10 votes
6 answers
1k views
Is my web server being compromised? [duplicate]
We logged remotely into our CentOS server today using Putty, and while wandering through previous commands using the up arrow, stumbled across the following: unset HISTFILE mkdir /usr/lib/tmp cd /...
3 votes
4 answers
3k views
I just got a linode VPS a week ago and I've been flagged for SSH scanning [duplicate]
Possible Duplicate: My server’s been hacked EMERGENCY I got a 32-bit Debian VPS from http://linode.com and I really haven't done any sort of advanced configuration for securing it ( port 22; ...
11 votes
3 answers
3k views
Has my Linux server been compromised? How do I tell? [duplicate]
Running (X)Ubuntu 10.04.2 LTS behind a router. I just received an email from my root account on that machine, with the following subject: *** SECURITY information for <hostname>: The message ...
2 votes
6 answers
2k views
Websites on Ubuntu 8.04 LTS with Plesk are infected with viruses [duplicate]
I am running Plesk 9.5 on Ubuntu 8.04 LTS and have about 15 websites infected with some malicious code appended to the end of java files. I have installed Clamav and it has managed to pickup the ...
3 votes
6 answers
4k views
I think my server is being hacked. What should I do? [duplicate]
Possible Duplicate: My server's been hacked EMERGENCY I'm not a server admin and I have very little experience in "debuging" a server. But from looking at my log files, it looks as if I'm ...
5 votes
2 answers
24k views
What do these entries in my SSH logs mean? [duplicate]
I recently noticed that I have entries from an unknown IP address in my SSH logs. I performed a grep to extract all entires that didn't contain my own IP address. I was presented with this: Jul 24 22:...
2 votes
1 answer
12k views
Why is the remote desktop service connected to a *random* IP? [duplicate]
Possible Duplicate: How do I deal with a compromised server? I noticed some unusual network behaviour on my Windows web server 2008 R2 x64 server, when I investigated on Resource Monitor I noticed ...