Go Back   Linux Forums by TotalPenguin! Get linux Help! > Linux > Linux Security

Linux Security Make your Linux box more secure - Learn How

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 06-28-2008, 10:22 PM
Tor Tor is offline
Senior Member
 
Join Date: Oct 2007
Posts: 384
Tor is on a distinguished road
Default Linux After Hacked?

How do you figure out how you were hacked and what IP hacked you after you have been hacked? I don't mean where you "think" you have been hacked but once your webpage says "Owned by..." or the data on your server is missing... What next? How do you identify how you were hacked?

Security seems like a big issue and I read about it all the time but I never read about what to do after you've been hacked. lol
Reply With Quote

Sponsored Links
  #2 (permalink)  
Old 06-29-2008, 03:29 PM
Jordan's Avatar
Administrator
 
Join Date: Nov 2006
Posts: 533
Jordan is on a distinguished road
Default

If you still have log files, check them! You'll spend hours pouring through them unless you know the exact time of the hack though.
Reply With Quote
  #3 (permalink)  
Old 06-30-2008, 02:17 PM
Member
 
Join Date: Jun 2008
Posts: 54
LissaValerian is on a distinguished road
Default

Quote:
Originally Posted by Jordan View Post
If you still have log files, check them! You'll spend hours pouring through them unless you know the exact time of the hack though.
Exactly what Jordan said,

LOGS LOGS LOGS. Keep LOGS! Thats where your information will be. If you watch the logs and look through them closely, you'll see exactly what you need to see.

There are software applications out there that will analyze logs for you and keep a nice graph, etc., I can't remember what they are at the moment, since I just look at the logs themselves. Now I'm not just talking about software that analyzes bandwidth, I'm talking about software that analyzes for security. I worked with some students who were grads in computer science and I help them set up a security system for one of their projects that analyzed the network and logs for security breaches, etc. I can't think of the name of that particular bit of software for the life of me ....

But LOGS are the key. Keep them. :-)
Reply With Quote
  #4 (permalink)  
Old 06-30-2008, 02:51 PM
Jordan's Avatar
Administrator
 
Join Date: Nov 2006
Posts: 533
Jordan is on a distinguished road
Default

I know logwatch is a very good program to have and to have it email you every day with reports. Which reminds me, for some reason I haven't received my logwatch in a couple of days.
Reply With Quote
Reply

Tags
hacked, linux

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Can you be hacked? EugenS Linux Security 2 06-22-2008 01:59 PM
Your linux box hacked? Penguin Linux Security 5 10-15-2007 11:04 PM


All times are GMT. The time now is 01:53 PM.


Powered by vBulletin® Version 3.7.0
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.