[Log In ] [New Posts] []
Go Back   GotApex? Forums Forums > General Topics > Suckage/Not-So-Suckage
User Name
Password

Reply
 
Thread Tools Search this Thread Display Modes
Old 08-29-2006, 03:27 PM   #1
Memo
Admiral
 
Memo's Avatar
 
Join Date: Apr 2001
Location: East Village
Posts: 5,659
SS: Work server hacked

So, the main server at work here got hacked and I have no idea how. Some ******* came in and changed the root password and deleted all other accounts, installed apache, an irc bounce, created a bunch of empty directories which seem to be preparing it to become a warez dump .
Memo is offline   Reply With Quote
Old 08-29-2006, 03:42 PM   #2
Cubsfan
Rear Admiral Lower Half
 
Cubsfan's Avatar
 
Join Date: Jul 2001
Location: Colorado
Posts: 2,743
Not very sneaky, are they? Seems like if they really wanted that plan to work, they wouldn't have necessarily changed the root passwords. That's likely to get noticed quickly.

What OS?
Cubsfan is offline   Reply With Quote
Old 08-29-2006, 04:20 PM   #3
Memo
Admiral
 
Memo's Avatar
 
Join Date: Apr 2001
Location: East Village
Posts: 5,659
Unix.

They didn't change the passwords on me till I stopped the Apache server they had installed. The ****tiest part is that I have no idea how they got in.
Memo is offline   Reply With Quote
Old 08-29-2006, 04:31 PM   #4
Cubsfan
Rear Admiral Lower Half
 
Cubsfan's Avatar
 
Join Date: Jul 2001
Location: Colorado
Posts: 2,743
Ahh, so they didn't change it until they knew they were caught. I'm guessing you can recover?
Cubsfan is offline   Reply With Quote
Old 08-29-2006, 04:58 PM   #5
Memo
Admiral
 
Memo's Avatar
 
Join Date: Apr 2001
Location: East Village
Posts: 5,659
We're running on the slave so we're ok for now, but I guess without finding the source of the intrusion I can't truly be "safe."

The kicker is the *******s at the IT department of our sister company changed the password to MY router here. When I inquired about it they denied changing it. They then admitted it and refused to give it to me because they didn't trust me with the bridge between our 2 LANs (eventhough I set it up and walked them through the set up of the router on their side ). It realy makes me think they are the ones who did this. Either way, I contacted directly to the Cisco router and recovered and changed the passwords myself.
Memo is offline   Reply With Quote
Old 08-30-2006, 08:17 AM   #6
Prngr44
Rear Admiral Lower Half
 
Prngr44's Avatar
 
Join Date: Feb 2003
Location: St. Louis
Posts: 2,620
Send a message via AIM to Prngr44 Send a message via Yahoo to Prngr44
Sounds like some drama!
Prngr44 is offline   Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -7. The time now is 09:12 AM.