Wow
This has been fun, but useful nevertheless.
The techinician who told me the system was hacked was relying on information he was getting back from using rkhunter.
What he had forgotten to do was update rkhunter prior to running the check, doh!
Another technician and myself got on gmailchat and worked it all out. They didn’t have to do that, and I’ve only had good expreiences from Rimu in the past, so Rimu get 8 out of 10, got to take 2 off for telling me it was hacked:-(
We also looked at some other problems, namely the server getting hammered by akamai servers from nowhere and the bandwidth flying through the roof, which was our initial indication of an intrusion. I’m waiting for an explanation from akamai about that.
The techinician then applied some iptables rules for me and the akamai stuff seemed to disappear.
In the 20 mins we had of thinking about how to rebuild I put together a plan of rsync’ing all the data to another host, hotcopy the datatbase and use pound to switch back and for if the sh*t goes down.
A simple human error not helped by some crazy stuff going on in akamai.
If I was a chinese hacker, akamai servers seem like a perfect place to start. I’m not by the way FBI man 😊
Akamai have replied to my 5 phone calls and 3 forms that I sent to the web with an email from someone saying they’d look at what’s happening. That’s after I spent 40 minutes on a transatlantic phone call explaing the problem to a first level of support geezer, who sounded like he was listening, and then passed me over to recorded message telling you to email them as there was no telehpone support. 😊 I was so chuffed. 0 out of 10 for akami so far, 10 out of 10 for EE, 8 out of 10 for Rimu.
Robin, cheers mate, as always your assistance has proved to be swift and accurate.
I’m sorry to bother you.