Forum archive
passwd:chauthtok
Hi,
I've just found that something very strange happens after I fount that some useres of my VM disapear.
Then I was looking into logs and a I found something related with:
passwd:chauthtok
in /var/log/auth.log
http://forum.slicehost.com/index.php?p=/discussion/1858/system-has-been-...
I traced the IP that changed and delete the users and it comes also form Romania.
What that mean? How can I protect my VM?
I my setup, I am only make public (internal port FW) the port 8080 but from the same log, I got that it was changed by the 55051 ssh2 port. :|
I dont know if I can revert back again my machine and what happen in the atack. I dont think that this was possible with linux :| any way :|
Correction: I was also FW the port 22 :( to public..