How to restore a hacked Linux Server

Marius Ducea has a great article on How to restore a hacked Linux Server. He provides a very practical baseline on how you should develop your own plan of action to restore a hacked Linux Server. These are the steps he recommends:

– Don’t panic. Keep your calm and develop a plan of actions
– Disconnect the system from the network
– Discover the method used to compromise the system
– Stop all the attacker scripts and remove his files
– Restore not affected services
– Fix the problem that caused the compromise
– Restore the affected services
– Monitor the system

I’ve a personal experience of restoring a hacked Linux Server. I agree with all of his recommended steps. Out of them, I think finding the method (security hole) used to compromise the system is most important, because if you don’t know this then the attacker can immediately use the same security hole to attack and compromise the system after you restore.

Be Sociable, Share!
Posted in Admin, HowTo, Links, Linux/Unix, Network, Random, Security, Technology

Leave a Reply

Your email address will not be published. Required fields are marked *

*

Recent Comments

FirstCandace on WinXP and OSX dual boot in MacBook Pro: I have noticed you don’t monetize your…(November 10, 2017, 11:32 pm)
From Wikipedia, the free encyclopedia – Ram Bahadur Bomjon on Buddha Boy attacked and injured a guy with his sword?: […] Niranjan (July 20, 2007). “Buddha Boy…(September 2, 2017, 5:07 pm)
Micle on How I Prepared and Passed CISSP : Nice Aritcle…(August 10, 2017, 8:51 am)
David on How I Prepared and Passed CISSP : I am very happy to read this…(August 10, 2017, 8:21 am)
95Russell on Simulating Cisco and Linux Networks: Hello blogger, i must say you have…(August 5, 2017, 8:30 pm)