1 |
> > Last night my host sent out a message that their database had been |
2 |
> > compromised. I contacted them this morning and it turns out that all |
3 |
> > of their trouble tickets were exposed. I checked my records and |
4 |
> > (stupidly) I had included my root password in an email to them about a |
5 |
> > year ago. I (stupidly) hadn't changed the password since. I've |
6 |
> > changed it now and rebooted the system, but what do you think? Do I |
7 |
> > need to start this thing over? |
8 |
> |
9 |
> equery check sys-process/procps |
10 |
> equery check sys-apps/coreutils |
11 |
|
12 |
These check out. |
13 |
|
14 |
> Make sure that none of the executable files have changed. |
15 |
> |
16 |
> Also, emerge and run app-forensics/rkhunter |
17 |
|
18 |
chkrootkit reports no problems whatsoever which is actually kind of |
19 |
weird as I remember some things being reported last time I ran it, but |
20 |
I looked into them then and they weren't a problem. |
21 |
|
22 |
rkhunter reports no problems but it says it couldn't determine the OS |
23 |
so MD5 checks were skipped. |
24 |
|
25 |
- Grant |
26 |
-- |
27 |
gentoo-user@g.o mailing list |