Rootkit Friends

Hello everyone. So far, so well, i’m feeling lazy. There ist nothing to do, and I don’t know how to go on. This is not a very nice feeling.

But things even get worse: Some days ago I noticed that the apache on my rootserver wasn’t responding as expected, so I had a look into the system and the running processes. I was very shocked when I saw a bunch of warbot scripts and friends and further more some unfriendly webserver running with www-data privileges (and serving SEVERAL backdoors). I’d been hacked! I the meantime I was able to track the error down to the mambo CMS serving www.jpoetry.net. Lately I was much too lazy to update it and so it got exploited. Currently i’m newly setting up everything with even less privileges, moving Jpoetry.net to the stories.jpoetry.net CMS. Its a lot of work…

’til then. Your starseeker

Leave a Reply