Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

hacked and in trouble!!

Status
Not open for further replies.
Jan 10, 2003
34
NG
Hi guys
My machine an E250 with Solaris 8 was hacked and these are my problems:
- ps -ef no longer lists all processes.
for example ps -ef | grep sendmail will not show anything though sendmail is running.

The other problem is that, i ran chkrootkit and its gives results that netstat is infected. can I replace netstat. Can I replce ps. Please assist.
 
Restore netstat and ps from backup. In fact, restore the whole system from a known good date.
 
I could have restored from good known state. I did not do any back-up. Is there another way?
 
Install the netstat and ps utitlities from CD?

But to be honest, if your machine is rooted, you don't known what they have done to it. Even if you clean the system from any known rootkits, you can't be sure it will get rid of everything. There could still be backdoors installed.

Fresh new install is the only really secure option. If you don't have any clean backups...

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top