OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Cracked, now what?
From: Mike (mikeIOLO.COM)
Date: Fri Aug 18 2000 - 14:42:43 CDT


Greetings:

I've just discovered my linux machine has been cracked with some toolkit
named .nfx. It looks like the cracker has created a few accounts, killed
all my logging processes, and altered a few programs (like ps), and added a
few programs like port scanners.

This machine is a file server and doesn't really contain anything
sensitive, or really anything worth stealing. Admittedly, I've been pretty
lax with security because of this. In other words, this isn't an urgent
situation. The system is pretty old and I've been meaning to update it
soon anyway.

Besides being pretty disturbed and the violation, the cracker is using my
machine to port scan other machines. That I feel is my responsibility to
remedy pretty quickly.

Okay. Now what? Is there anything I can do to try to bust this guy before
I just redo the system from scratch? Any suggestions here?

TIA