Server is being hacked...

Well.. Too bad that my server is being hacked by someone, and inject some zombie code to attack other servers. I found that on last night, clean those zombie code, change admin password and so on. BTW, it is still too late that No-IP have already block my user account... I should check my server more often.

Anyway, just create another new account, and temporary move the site as http://edin.no-ip.info/. Whenever the problem solved, I will move back to http://edin.no-ip.com/. Sorry for any inconvenience due to the server down and migration :-(

Update (2008-05-14): Thanks for the help from Adam LaForge, the Manager of No-IP Technical Support, domain name is now back. As No-IP Support Ticket System promise for a response within 24hrs, after I provide a detail report about my site illegal traffic and what I have done as follow up action, Adam give me a fast and kindly warning, active my No-IP user account once again.

As a repair action, I have upgrade the latest Debian packages with:

apt-get update && \
apt-get upgrade -y && \
apt-get dist-upgrade -y && \
apt-get clean && \
apt-get autoclean && \
apt-get autoremove

Also install tripwire for system monitoring (I may write a detail instruction for tripwire soon):

apt-get install tripwire

The most possible reason of system hijack that I am able to figure out is the critical bug of Debian's OpenSSH package (http://www.debian.org/security/2008/dsa-1571). This announcement published on 2008-05-13, affect MOST Debian based system since 2006-09-17. As my server was being hacked on 2008-05-12 night, with hacker running as root from remote host, I may only guess this is a unluckily 0-day attack (http://en.wikipedia.org/wiki/Zero-Day_Attack).

I first notice this critical problem when there is an abnormal update of OpenSSH package during system upgrade: it ask me to regenerate ALL SSH certificate if possible; on the other hand, when double check my archived Debian Security mailing list record, finally I realize how complicated and critical of this problem... Again, I should check my email message more often and detail...


Post new comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <h1> <h2> <h3> <h4> <h5> <h6> <em> <strong> <code> <del> <blockquote> <q> <sub> <p> <br> <ul> <ol> <li> <dl> <dt> <dd> <a> <b> <u> <i> <sup> <acronym> <pre> <img>
  • Lines and paragraphs break automatically.
  • You may post code using <code>...</code> (generic) or <?php ... ?> (highlighted PHP) tags.
  • Images can be added to this post.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
Image CAPTCHA
Copy the characters (respecting upper/lower case) from the image.