Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 20 Nov 98 15:39:21 +0100
From:      Thierry.Herbelot@alcatel.fr
To:        mike@cctinc.net
Cc:        freebsd-questions@FreeBSD.ORG
Subject:   I need some help.
Message-ID:  <H000057c01a3aeb5@MHS>
In-Reply-To: <36557493.A9E1BBC@cctinc.net>

next in thread | previous in thread | raw e-mail | index | archive | help
> Hello,
>     I have two quick questions for you....I hope you can help me.
> 
>     1. I am building a new server and adding larger hard disks.  I have
> already created all the files systems (/, var/ usr/) and made the main
> drive boot able.  What I need to knwo is how do I make the procfs file
> system? I don't believe it is a real file system but something the
> server creates on its own.  I tried to mount it but it would not work.
> Do I have to worry about it or will the system just mount it when I
> restore all the existing data to the new drive and boot up?
> 
>     2.  I have been having a problem with spam the last few days and I
> have been attempting to block it.  However one guy keeps getting in.  I
> got this message in my process list when I used a ps-ax;
>  2070  ??  I      0:00.00 this iz mY 3l1t3 baCkd00r (bind)
> What is this?  Is there a security hole in Free BSD?

There are security holes in any system (any machine) if it is not cared
for. FreeBSD seems to have less "built-in" holes than other altenatives.
That said :
You've almost certainly been hacked
==> isolate your machine from Internet as soon as possible (to get it out
of reach of a hacker)
==> back up all the **data** that you have on the machine
==> reformat your disk and reinstall all your software from a **known
good** media (obviously not from a backup, as it may have been corrupted)
==> read about computer security (I don't have references, but the
FreeBSD www site has a good bibliography)
==> there is also a web page on "FreeBSD hardening" referenced from
FreeBSD (search for it with the <search> button on the first page of the
site)

	Hope you will recover

	TfH
> 
> I am getting concerned about this.  I have a lot of clients hosting
with
> my server and from what this looks like there is a backdoor someone is
> using on my server.  Can you please help me?
> 
> Thank you for your time!
> Mike Alich
> 
> 
> --
> Mike Alich
> mike@cctinc.net
> Cyber Communication Technologies, Inc.
> Web Hosting and Internet Solutions.
> http://www.cctinc.net
> Virtual Web Hosting $14.95 per month
> 
> 
> 
> To Unsubscribe: send mail to majordomo@FreeBSD.org
> with "unsubscribe freebsd-questions" in the body of the message


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?H000057c01a3aeb5>