If your server is compromised
It happens, including to careful people. What decides how bad it gets is the first hour.
First: contain, do not panic-delete
Resist the urge to clean up. The traces are the only way to find out how they got in, and if you destroy them you will be compromised again next week through the same door.
- Block traffic at the firewall or, if the machine is attacking others, take it off the network. Tell us — we would much rather hear it from you than from an abuse report.
- Copy the logs, the running process list and the crontabs somewhere else before you touch anything.
- Rotate every credential the machine held: SSH keys, database passwords, API tokens, anything in a config file. Assume all of it is known.
Then: how did they get in?
In our experience it is nearly always one of four things: an application left
unpatched, a database or cache exposed to the internet, a weak or reused password, or
a key that leaked. Check auth.log, your web server logs around the first
odd behaviour, and what is listening with ss -ltnp.
Then: rebuild, do not disinfect
A compromised machine cannot be trusted again. Rootkits hide from the tools you would use to find them. Reinstall, restore data from a backup made before the compromise, patch the hole, and only then put it back online.
Reinstalls are free and unattended here, so this costs you time rather than money.
What we do
If the machine is attacking others or sending spam we will act — that is our policy and it applies even when you are the victim. Work with us and it stays a short incident. Ignore the mails and it becomes a suspension, which helps nobody.
We will not log into your server to clean it, because we cannot: it is unmanaged and we hold no credentials on it.
Still stuck? Mail support@novogara.com — an engineer answers, at any hour. Back to the knowledge base