Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 1 Mar 2005 22:12:03 -0500
From:      Ean Kingston <ean@hedron.org>
To:        freebsd-questions@freebsd.org
Subject:   Re: recovering root password, was Help!Help!Help!
Message-ID:  <D9D7E36F-8AC8-11D9-ABB8-000A95D73348@hedron.org>
In-Reply-To: <001d01c51ed2$a6afc630$504b4646@Fullersoffice>

next in thread | previous in thread | raw e-mail | index | archive | help

On Tuesday, March 1, 2005, at 09:50  PM, Replies wrote:

> Hi,
>
> I have just spent over the last two years developing a unique 
> classified ads service which was online and had Free BSD as the 
> security on it. We ended up with a very aggressive and belligerent 
> programmer who left us but left us some nasty little bugs behind to 
> really screw us up.. who we now can't find.
>
> I need to know how to change or eliminate a root password.
>
> As I still have our "test server" in my possession is there any way to 
> actually remove the folder that the passwords are held in.....the 
> reason I ask this is that when we actually changed the password on our 
> "production server" it released some sort of worm that totally crashed 
> and eliminated our online site, and all our data we have spent two 
> years developing. It also started trying to access other sites which 
> we only found out about this when our site crashed and we got 
> compalints our from our ISP that our server was trying to agressively 
> access other servers out there on the net.
>
> The Only saving grace is that we had it all backed up on our test 
> server but it has the same problem...I expect...I believe that he has 
> probably left us the same worm in our test server....the unfortunate 
> thing is that because we do not know the root password we are worried 
> that if we try to crack or eliminate it the same thing may 
> happen...and then we are automatically out of business.
>
> Is there any way around this....I can prove I am the owner of the 
> site...the URL and the server and any other information you may need 
> if necessary....
>

First, make another backup of your test server. You may want to do this 
by building a new system with a fresh install of FreeBSD, physically 
removing the hard drive from your test server, installing it as a 
second drive (not the boot drive) in your newly created server, and do 
the backup (to tape, cd, or dvd).

Then, after the backup, change the root password in the test servers 
hard drive. If you mount the root partition from the test server's hard 
drive as /mnt you could use vipw -d /mnt/etc to do it.

Finally, take the advice you got from Chris.

>
> I really need help as this is 2/12 years work as it stands gone.
>
> Thanks
> God Bless
> Freddy
> _______________________________________________
> freebsd-questions@freebsd.org mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-questions
> To unsubscribe, send any mail to 
> "freebsd-questions-unsubscribe@freebsd.org"



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?D9D7E36F-8AC8-11D9-ABB8-000A95D73348>