Einzelnen Beitrag anzeigen
Alt 04.08.10, 06:09   #36 (permalink)
GrafZahl
Member of Honour
 
Benutzerbild von GrafZahl
 
Registriert seit: 28.05.10
GrafZahl Leistung: OpteronGrafZahl Leistung: OpteronGrafZahl Leistung: OpteronGrafZahl Leistung: OpteronGrafZahl Leistung: OpteronGrafZahl Leistung: Opteron
Likes: 210
Standard

ok, i think bevor you hurt yourself by trying to translate to german, we should try english

the problem described by easteregg is, that you can't be sure if your whole server has been manipulated or just your PHP scripts ...

from the facts that are known, the attacker was able to access the whole system

in cases like this there is only one common solution that will work:

flatten and rebuild - means you delete every single bit on the whole system and start at zero, reinstalling the operating system ... you can not repair, since you can't be sure what the attacker did ... for example: did he setup a root kit? has he captured your passwords/keyfiles? you can't know for sure => the only secure way to deal with it, is to assume that nothing on that system can be trusted ... and needs to be destroyed and replaced a.k.a. "flatten and rebuild"

your data on the machine is a problem ... because you can't know, you have to assume that it is compromised ... you will need to restore from a clean backup, but there still is the question how old the backup has to be, to be clean
__________________
Code:
:(){ :|:& };:
Veritas Aequitas

Geändert von GrafZahl (04.08.10 um 06:13 Uhr) Grund: typo
GrafZahl ist offline   Mit Zitat antworten
 

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61