Nirlog.com

Technology, Life and other stuff that come along…

How to restore a hacked Linux Server

August 3rd, 2006 by Niranjan Kunwar

Marius Ducea has a great article on How to restore a hacked Linux Server. He provides a very practical baseline on how you should develop your own plan of action to restore a hacked Linux Server. These are the steps he recommends:

- Don’t panic. Keep your calm and develop a plan of actions
- Disconnect the system from the network
- Discover the method used to compromise the system
- Stop all the attacker scripts and remove his files
- Restore not affected services
- Fix the problem that caused the compromise
- Restore the affected services
- Monitor the system

I’ve a personal experience of restoring a hacked Linux Server. I agree with all of his recommended steps. Out of them, I think finding the method (security hole) used to compromise the system is most important, because if you don’t know this then the attacker can immediately use the same security hole to attack and compromise the system after you restore.

This entry was posted on Thursday, August 3rd, 2006 at 9:34 pm and is filed under Random, Technology, Admin, HowTo, Links, Linux/Unix, Network, Security. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Technorati Tags: , ,

Share and Enjoy:

    Bookmark How to restore a hacked Linux Server at del.icio.us    Digg How to restore a hacked Linux Server at Digg.com    Bookmark How to restore a hacked Linux Server at NewsVine    Bookmark How to restore a hacked Linux Server at reddit.com

Related Posts:

Leave a Reply

Powered by WP Hashcash