1 |
> > Last night my host sent out a message that their database had been |
2 |
> > compromised. I contacted them this morning and it turns out that all |
3 |
> > of their trouble tickets were exposed. I checked my records and |
4 |
> > (stupidly) I had included my root password in an email to them about a |
5 |
> > year ago. I (stupidly) hadn't changed the password since. I've |
6 |
> > changed it now and rebooted the system, but what do you think? Do I |
7 |
> > need to start this thing over? |
8 |
> > |
9 |
> > - Grant |
10 |
> |
11 |
> I think you should take a look at the programs that |
12 |
> are running, and netstat -l, and see if anything is fishy. |
13 |
|
14 |
I recognize everything in 'ps -ef' I think, but I've never really used |
15 |
netstat before. Under "Active Internet connections" I don't |
16 |
recognize: |
17 |
|
18 |
tcp localhost:10030 |
19 |
tcp *:snpp |
20 |
|
21 |
I don't recognize most of the paths under UNIX domain sockets. |
22 |
Anything particular I should look for? |
23 |
|
24 |
- Grant |
25 |
-- |
26 |
gentoo-user@g.o mailing list |