Server Security and tracking

gmloki

Part of the furniture
Joined
Dec 22, 2003
Messages
634
I have a 1U server running Suse 9.2 on it. It is currently hosted at 49pence at Redbus in London. It is used for hosting a few public game servers. We all chipped in some money to pay for it etc.

Anyway one of the guys who was involved has split and in an acrimonious kind of way. Basically we keep getting all sorts of processes set off on the server which result in resource or bandwith whorage.. We have spoken with our hosts and they feel that it is malicious attacks. We have removed any access he had via webmin.

We cant prove it was him but all fingers point there. Now is there any covert way we can track if someone sets off a process or if they have access through a back door. What other security counter measures can be used on a linux server other than a conventional firewall etc.

Apologies for the vaguries of this as I must admit I am more of a Winblows Boy and I have not used Linux that much. If I can offer any info then plase let me know

Many thanks
 

TdC

Trem's hunky sex love muffin
Joined
Dec 20, 2003
Messages
30,925
the server should log every authentication re date/time/username/ip success or failure. unless he's a bright lad and cleans up after himself that is.

I take it you all use the same user to log into the webmin / ssh / whatever? that makes things more tricky, but you could present your hosting company with a list of known-good IP addys, and they could then filter the bad man out.
 

Users who are viewing this thread

Top Bottom