In Summary, a rootkit is a trojan installed on your Linux server after someone has broken into it. These files are used to cover the hackers tracks, and to give the hacker tools to do more dirty work from your server.
Usage:
1. su - (change to root user) 2. mkdir /usr/local/chkrootkit 3. wget ftp://ftp.pangeia.com.br/pub/seg/pac/chkrootkit.tar.gz 4. tar -xvzf chkrootkit.tar.gz 5. cd chkrootkit* 6. cp * /usr/local/chkrootkit 7. cd /usr/local/chkrootkit 8. make sense
Now scan your system:
1. cd /usr/local/chkrootkit 2. ./chkrootkit
chkrootkit may from time to time give false positives. If you ever get a positive or "infected hit" scan a second time. If you do get a positive hit, google the hit to research the issue and steps to correct.
Part 2 - automated chkrootkit, and emailed results.
I'm lazy, and like my server to do the work for me so I have it scan every day, and email me the results.
Usage:
1. vi /etc/cron.daily/chkrootkit 2. add the following code.
Code: ---------------------- Start Rootkit Hunter Scan ---------------------- Warning: Checking for prerequisites [ Warning ] The file of stored file properties (rkhunter.dat) does not exist, and so must be created. To do this type in 'rkhunter --propupd'. Warning: WARNING! It is the users responsibility to ensure that when the '--propupd' option is used, all the files on their system are known to be genuine, and installed from a reliable source. The rkhunter '--check' option will compare the current file properties against previously stored values, and report if any values differ. However, rkhunter cannot determine what has caused the change, that is for the user to do.
One or more warnings have been found while checking the system.
Please check the log file (/var/log/rkhunter/rkhunter.log)
One of my users posted this in the forum saying my server is scanning his computer. His this serious? Do I have virus? Should i be worried? Well i am kinda worried. I tried googling it, but i can't seem to figure the right keywords for a good result.
has anyone successfully updated from bind9.2.x to BIND 9.5.0-P1? Were there any problems regarding settings, zone files, etc etc? Can you explain the process in detail for the update? One of my customers wishing to have this done, is running CentOS, I assume yum would be the best course of actions?
When you are hosting websites/game servers and then updates on your server pops up. What do you do? Restart the server and kick everyone off the server for 10min? Or leave it?
Lately we have been receiving a lot of complaints from our users who do not wish to update their scripts. I have been telling those users that they have to keep their scripts up to date if they want to avoid having that script exploited or used to send spam or other malicious intentions. The ramifications of a single user on a server not keeping their script up to date affects all of the users on the server.
I am just wondering how other hosting providers handle this. When a client threatens to leave because you don't allow them to run an outdated script, what actions do you take to try and keep the client?
I have a Windows VPS account with a well-known hosting company. According to their knowledgebase, they "apply Microsoft security updates directly from the hardware node. For this reason, they are not able to be applied from within your VPS."
I discovered this after attempting to apply a Service Pack on my VPS, which messed up my VPS. Now that I've learned this the hard way, here's my question: Is this true with other Windows VPS hosting companies too?
While I understand that I'm responsible for what I update on my VPS, I'm frustrated that the hosting company doesn't take more steps to prevent this from happening...
cPanel has released a very important update a short while ago. I don't normally post when updates are released, but this is one that should not be missed. More information can be found here: [url]
and here: [url](not sure when this will be updated).
Stay safe.
edit: the *second* I posted this, I found out there will be another tomorrow. Keep your eyes on layer1.cpanel.net.
I've been trying to get any reviews on ahosting.biz services here on the forum, but the last thread where the poster was complaining about the limits of emails sent from their reseller accounts failed to find anything. Any updates?
I have been with primaryvps since May and in last two months I was very busy... and then came back from vacation, it was working fine for a few days... indeed, I could access my server as late as last night. But then my server is down today, with empty page at primaryvps.com and there's nothing else.
So I got nervous and came here to check... and I realized that a lot of people had troubles with them, perhaps more than I did, but then are they really going out of business? As a customer I received no warning of any kind, though.
Any certain info on their current status would be appreciated. I wrote them (support and victor's email) but didn't get responses... In the past they replied very fast, so there's something strange going on for sure...
I'm running Plesk 9.2.2 & using the supplied AWStats install. Where will I find the configuration that dictates when AWStats will be updated? It's currently updating at 3.36am daily, & I'd like to set it to hourly. Can't find anything in the root or psaadm crontabs & not sure where else to look.
Basically I do all my updating now. I have a VPS with...*GASP*...godaddy and their policy is you do all the updating to your server yourself. They will not help you in any way unless you pay their "extra special services team" 80 bucks an hour.
Now, I'm not that much of a server genius, I can find my way around and do certain updates. I'm just tired of doing it and also have a huge fear that I'll screw something up.
Is there a company that will do a full switchover from godaddy to their service, does all the updates and installs programs for a small fee for you? I also need one that is comparable in price. I'm paying 52 bucks a month now.