root exploits
Posted: 11 Jan 2013, 23:34
Hi,
I'm using CSF (btw, where can I see which version is it?) and I just found one of my servers has been hacked.
Looking at the /var/log/lfd.log, I see that a user which was created by the attacked ("ghost") is using a security exploit to gain root, but I didn't get any email nor did I find the following details:
1. Which security exploit is it?
2. How can I automatically block the offending IP?
I looked accross the csf.conf and I didn't find anywhere such options. Could you please tell me which options to set the 2 items?
How do I really see which security exploit that damn kid used? this is the most important issue for me..
One last thing: I was hacked by this "Ghost Iraq" - any good web site where I can find which exploit they use and how I can block it?
Thanks,
Hetz
I'm using CSF (btw, where can I see which version is it?) and I just found one of my servers has been hacked.
Looking at the /var/log/lfd.log, I see that a user which was created by the attacked ("ghost") is using a security exploit to gain root, but I didn't get any email nor did I find the following details:
1. Which security exploit is it?
2. How can I automatically block the offending IP?
I looked accross the csf.conf and I didn't find anywhere such options. Could you please tell me which options to set the 2 items?
How do I really see which security exploit that damn kid used? this is the most important issue for me..
One last thing: I was hacked by this "Ghost Iraq" - any good web site where I can find which exploit they use and how I can block it?
Thanks,
Hetz