Gentoo Archives: gentoo-user

From: Grant <emailgrant@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Hacked by association?
Date: Wed, 19 Sep 2007 18:51:59
Message-Id: 49bf44f10709191136u7157bceet52b7b5b06ec9d6ac@mail.gmail.com
In Reply to: Re: [gentoo-user] Hacked by association? by Dan Farrell
1 > > Last night my host sent out a message that their database had been
2 > > compromised. I contacted them this morning and it turns out that all
3 > > of their trouble tickets were exposed. I checked my records and
4 > > (stupidly) I had included my root password in an email to them about a
5 > > year ago. I (stupidly) hadn't changed the password since. I've
6 > > changed it now and rebooted the system, but what do you think? Do I
7 > > need to start this thing over?
8 > >
9 > > - Grant
10 >
11 > I think you should take a look at the programs that
12 > are running, and netstat -l, and see if anything is fishy.
13
14 I recognize everything in 'ps -ef' I think, but I've never really used
15 netstat before. Under "Active Internet connections" I don't
16 recognize:
17
18 tcp localhost:10030
19 tcp *:snpp
20
21 I don't recognize most of the paths under UNIX domain sockets.
22 Anything particular I should look for?
23
24 - Grant
25 --
26 gentoo-user@g.o mailing list

Replies

Subject Author
Re: [gentoo-user] Hacked by association? Ryan Sims <rwsims@×××××.com>
Re: [gentoo-user] Hacked by association? Mick <michaelkintzios@×××××.com>