PDA

View Full Version : [ubuntu] server mysql compromised



perfectpol7
February 16th, 2011, 04:43 PM
My Linux server which is running my company website have been hacked. Today I saw a number of clients (customers) names with some fun characters entries on my database (mySql). Access denial on really clients. Please assist, am running Linux Ubuntu 9 and I dont know where to start troubleshooting this. let me confession that I am still on the learning curve on Linux

tgalati4
February 16th, 2011, 05:30 PM
If you have physical access to the machine, you need to disconnect it from the web (unplug it) and put in the LiveCD (desktop or server addition) it doesn't matter. You will need to reset the mysql root user password, probably the root login password as well. You are going to boot into the "Rescue" mode using the LiveCD and then follow the helpful commands that others will guide you through to regain control of your system.