From owner-freebsd-questions@FreeBSD.ORG Mon Mar 8 10:56:15 2004 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id D11BA16A4CE for ; Mon, 8 Mar 2004 10:56:15 -0800 (PST) Received: from webmail-outgoing.us4.outblaze.com (webmail-outgoing.us4.outblaze.com [205.158.62.67]) by mx1.FreeBSD.org (Postfix) with ESMTP id C15A843D31 for ; Mon, 8 Mar 2004 10:56:15 -0800 (PST) (envelope-from qt4x11@linuxmail.org) Received: from spf9.us4.outblaze.com (spf9.us4.outblaze.com [205.158.62.169]) AFA2A180098F for ; Mon, 8 Mar 2004 18:56:15 +0000 (GMT) X-OB-Received: from unknown (205.158.62.132) by wfilter.us4.outblaze.com; 8 Mar 2004 18:56:02 -0000 Received: by ws5-2.us4.outblaze.com (Postfix, from userid 1001) id 9C4CC4160BD; Mon, 8 Mar 2004 18:56:15 +0000 (GMT) Content-Type: text/plain; charset="iso-8859-1" Content-Disposition: inline Content-Transfer-Encoding: 7bit MIME-Version: 1.0 X-Mailer: MIME-tools 5.41 (Entity 5.404) Received: from [129.105.51.116] by ws5-2.us4.outblaze.com with http for qt4x11@linuxmail.org; Tue, 09 Mar 2004 02:56:15 +0800 From: "re re" To: freebsd-questions@freebsd.org Date: Tue, 09 Mar 2004 02:56:15 +0800 X-Originating-Ip: 129.105.51.116 X-Originating-Server: ws5-2.us4.outblaze.com Message-Id: <20040308185615.9C4CC4160BD@ws5-2.us4.outblaze.com> Subject: hacked X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 08 Mar 2004 18:56:15 -0000 hello despite having ipfilter blocking all ports except 80 21 and 22, tripwire, and scoring 999999 in nmap, my website got defaced. the box is currently unplugged. i wanted to know what is the best way to find out who did it and how they got in, and what to do from here. tripwire shows a lot of files changed, most of which could be attributed to cvsup'ing recently. any other security precautions to take disaster recovery guides? i've already changed p/w's on my other boxes. thanks -- ______________________________________________ Check out the latest SMS services @ http://www.linuxmail.org This allows you to send and receive SMS through your mailbox. Powered by Outblaze