Re: ssh binary modified
Hello,
yeah, that box has been taken over. Now, before you nuke it and
reinstall from some trusted media, I'd try and give finding out what
exactly happened a shot. My point is that if they got in through e.g. a
flaw in a custom web app, just newly setting up the machine and
resetting the passwords is not going to make it all go away.
You don't have to be a forensics expert to at least have a long good
look at the log files.
Cheers,
Jan
_______________________________________________
freebsd-security@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
討論串 (同標題文章)
完整討論串 (本文為第 4 之 6 篇):