Page 1 of 1

Hacked?! need to reset my root pw

Posted: Mon Nov 20, 2006 3:50 pm
by cyesergio
Hey guys,

Uhm, I feel kind of embarassed asking this question. I think somebody hacked my xbox server and changed my root pw. There's nothing useful on it yet (well some stuff). How do I reset my gentoox password. And do you guys have any specific tips or pointers on security?

Thanks in advance,

Cye

Posted: Tue Nov 21, 2006 6:48 am
by orochi
dang that stucks.


Im not sure but you might be able to just inject your own password hash into the /etc/passwd file (or is it /etc/shadow)


either way, I would suggest you backup your data then completely reinstall, you can never trust that box after it has been compromised.

Posted: Tue Nov 21, 2006 5:50 pm
by ShALLaX
Boot up Resctoox, mount your Gentoox installation, chroot to it and then run `passwd`.

Security - dont let other people use your box. Dont even bother trying to recover your installation, just start again. The chances that the guy installed a rootkit are rather high :/

Posted: Wed Nov 22, 2006 5:29 pm
by cyesergio
ShALLaX wrote:Boot up Resctoox, mount your Gentoox installation, chroot to it and then run `passwd`.

Security - dont let other people use your box. Dont even bother trying to recover your installation, just start again. The chances that the guy installed a rootkit are rather high :/
Geez...ok thanks for the tip