Re: breakin help

2004-09-13 Thread Kevin Mark
On Mon, Sep 13, 2004 at 10:06:05PM -0400, Adam Aube wrote: > Kevin Mark wrote: > > > There are no top secret things on my system, so full reinstall is not an > > urgency. > > You have disk space and bandwidth - many times that's all an attacker wants. > > > I also checked 'top' for any unexpecte

Re: breakin help

2004-09-13 Thread Adam Aube
Kevin Mark wrote: > There are no top secret things on my system, so full reinstall is not an > urgency. You have disk space and bandwidth - many times that's all an attacker wants. > I also checked 'top' for any unexpected processes and there was none.of > course if top,ps and the kernel were re

Re: breakin help

2004-09-12 Thread Kevin Mark
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Sun, Sep 12, 2004 at 10:29:39AM -0400, Adam Aube wrote: > Kevin Mark wrote: > > > # Use SSH keys instead of passwords for authentication > PubkeyAuthentication yes > PasswordAuthentication no > > 3) Report this attack to the owner of the IP bloc

Re: breakin help

2004-09-12 Thread Adam Aube
Kevin Mark wrote: > a day ago, I had a problem with su-ing to root. I checked out my auth.log > and found strange activity. I have a basic ipchains script and run apache > and sshd on a dialup connection. Consult: > http://kmark.home.pipeline.com/breakin.txt > as I did not want to overload the lis

Re: breakin help

2004-09-12 Thread Stefan O'Rear
On Sun, Sep 12, 2004 at 02:19:47AM -0400, Kevin Mark wrote: > Hi D-U, > a day ago, I had a problem with su-ing to root. I checked out my auth.log and > found strange activity. I have a basic ipchains script and run apache > and sshd on a dialup connection. Consult: > http://kmark.home.pipeline.com/