[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [cobalt-users] last bit of hacker droppings.



+just delete the poor little thing.... /var/spool/cron  under root
+put the little bugger to bed.....btw the init file is a hacked
+one...we just
+had 3 raq3's with it...
+they keep ticking...and working..except SOME can not retrieve email...so
+fromt the 3 machines...we restored one, did ALL the updates, and move the
+sites where they could nto retrieve the mail from to the restored
+one....works like a charm , and until we have a lot of time or until users
+can get their emial, we just SLOWLY move sites from one to the
+other.....and
+yes in the future we are going to keep 1 virgin raq around

Resolved that, thanks. Killed the bogus init and restored the other bogus
system files.
Just installed logcheck and netstat shows these ports which I didn't see
before:

udp        0      0 0.0.0.0:7938            0.0.0.0:*
raw        0      0 0.0.0.0:1               0.0.0.0:*               7
raw        0      0 0.0.0.0:6               0.0.0.0:*               7

Any idea what ports these are?

Tony