Full Disclosure mailing list archives
Re: one of my servers has been compromized
From: Kerem Erciyes <kerem.erciyes () gmail com>
Date: Tue, 6 Dec 2011 17:29:12 +0200
I regularly use iftop, netstat and htop to see what is going on on my servers. I have found that raw information always helps the best in determining acitve compromised systems. Kerem On Tue, Dec 6, 2011 at 11:55 AM, Lucio Crusca <lucio () sulweb org> wrote:
BH wrote:I'm not sure if this has been said in this thread yet, but is it possible the host O/S was compromised?Nothing is impossible, security wise. However I'd talk about likelihood instead. I own two other OpenVZ containers hosted in the same host OS. They haven't been compromised, though they're very similar systems (Debian based instead of Ubuntu). The one that has been compromised is the only one having a online shop and greater network traffic. _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
-- Kerem Erciyes - Sistem Danismani http://keremerciyes.com
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Re: one of my servers has been compromized, (continued)
- Re: one of my servers has been compromized Valdis . Kletnieks (Dec 06)
- Re: one of my servers has been compromized John Jacobs (Dec 06)
- Re: one of my servers has been compromized Gage Bystrom (Dec 06)
- Re: one of my servers has been compromized Dan Ballance (Dec 05)
- Re: one of my servers has been compromized Gage Bystrom (Dec 05)
- Re: one of my servers has been compromized Javier Bassi (Dec 05)
- Re: one of my servers has been compromized Dan Ballance (Dec 05)
- Re: one of my servers has been compromized Lucio Crusca (Dec 06)
- Re: one of my servers has been compromized BH (Dec 06)
- Re: one of my servers has been compromized Lucio Crusca (Dec 06)
- Re: one of my servers has been compromized Kerem Erciyes (Dec 06)
- Re: one of my servers has been compromized Gage Bystrom (Dec 06)
- Re: one of my servers has been compromized Valdis . Kletnieks (Dec 06)
- Re: one of my servers has been compromized Paul Schmehl (Dec 06)
- Re: one of my servers has been compromized Gage Bystrom (Dec 06)
- Re: one of my servers has been compromized Paul Schmehl (Dec 06)
- Re: one of my servers has been compromized Charles Morris (Dec 06)
- Re: one of my servers has been compromized Gage Bystrom (Dec 06)
- Re: one of my servers has been compromized Paul Schmehl (Dec 07)
- Re: one of my servers has been compromized Gage Bystrom (Dec 07)
- Re: one of my servers has been compromized Paul Schmehl (Dec 07)