Re: [Hampshire] [OT?] This is odd...

Top Page

Reply to this message
Author: Jacqui Caren-home
Date:  
To: Hampshire LUG Discussion List
Subject: Re: [Hampshire] [OT?] This is odd...
Hugo Mills wrote:
>    I'm guessing UPnP in an embedded device of some kind.


If the box is not running the services you had previously, I would suspect the machine has been hacked - if you have webmail ssh or ftp open
there has been/still is some heavy targetted brute force attacks ongoing.
We lost a vserver last week and luckily we had a backup so just shut down the zv instance
replaced it withe the backup image and hit restart (ish).

The dog rescue I discussed in a different thread is being hit by many such infected
servers that seem to be being used to brute force web/ftp/ssh passwords.

Jacqui