S
sharingsunshine@
Guest
Helo,
I have reason to believe someone got thru our firewall via telnet. I can't find any evidence that they were able to accomplish anything before I found them.
I realize they can change the log files. So, I wanted to install a good Virus, Trojan detector on my Redhat Enterprise version 3ES.
Can you suggest one?
Here is the log on logwatch that made me think they hacked the server.
************
Service telnet:
220.225.128.155: 2 Time(s)
---------------------- Connections (secure-log) End -------------------------
--------------------- SSHD Begin ------------------------
Users logging in through sshd:
root logged in from va-69-34-35-58.sta.sprint-hsd.net (69.34.35.58) using password: 3 Time(s)
SFTP subsystem requests: 1 Time(s)
---------------------- SSHD End -------------------------
--------------------- up2date Begin ------------------------
Package Installed:
['nss_ldap-207-17', 'openldap-2.0.27-20', 'openldap-clients-2.0.27-20', 'openldap-devel-2.0.27-20']
Package Added To Profile:
['nss_ldap-207-17', 'openldap-2.0.27-20', 'openldap-clients-2.0.27-20', 'openldap-devel-2.0.27-20']
Package Removed From Profile:
['nss_ldap-207-15', 'openldap-2.0.27-17', 'openldap-clients-2.0.27-17', 'openldap-devel-2.0.27-17']
**Unmatched Entries**
Unable to import repomd support so repomd support will not be available
Updating package profile
---------------------- up2date End -------------------------
*********************
Thanks, any help will be greatly appreciated.
Randal
I have reason to believe someone got thru our firewall via telnet. I can't find any evidence that they were able to accomplish anything before I found them.
I realize they can change the log files. So, I wanted to install a good Virus, Trojan detector on my Redhat Enterprise version 3ES.
Can you suggest one?
Here is the log on logwatch that made me think they hacked the server.
************
Service telnet:
220.225.128.155: 2 Time(s)
---------------------- Connections (secure-log) End -------------------------
--------------------- SSHD Begin ------------------------
Users logging in through sshd:
root logged in from va-69-34-35-58.sta.sprint-hsd.net (69.34.35.58) using password: 3 Time(s)
SFTP subsystem requests: 1 Time(s)
---------------------- SSHD End -------------------------
--------------------- up2date Begin ------------------------
Package Installed:
['nss_ldap-207-17', 'openldap-2.0.27-20', 'openldap-clients-2.0.27-20', 'openldap-devel-2.0.27-20']
Package Added To Profile:
['nss_ldap-207-17', 'openldap-2.0.27-20', 'openldap-clients-2.0.27-20', 'openldap-devel-2.0.27-20']
Package Removed From Profile:
['nss_ldap-207-15', 'openldap-2.0.27-17', 'openldap-clients-2.0.27-17', 'openldap-devel-2.0.27-17']
**Unmatched Entries**
Unable to import repomd support so repomd support will not be available
Updating package profile
---------------------- up2date End -------------------------
*********************
Thanks, any help will be greatly appreciated.
Randal