<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Virus Attack or Have I been Hacked? in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/virus-attack-or-have-i-been-hacked/m-p/2465366#M759948</link>
    <description>I CANN'T LOG INTO MY SERVER FROM ANY WHERE (INCLUDING CONSOLE), BOTH TELNET AND RLOGIN ARE NOT WORKING!&lt;BR /&gt;AND THE SYSTEM DISK ARE SHOWING BUSY BLINKING LIGHT, THE LCD HAS JUST F13F ON DISPLAY.&lt;BR /&gt;HOW CAN I GO INTO THE SERVER TO CHECK THE DIRECTORIES. SINCE CONSOLE LOGIN IS NO LONGER WORKING. WHEN I RUN 'HPUX LL' AT ISL&amp;gt;, IN SEE THAT ALL IDS IN /STAND WERE CHANGED TO USER AND GROUP ID NUMBERS. VMUNIX, SYSTEM AND THE *.PREV FILES ARE ALL ZERO. THEY GUYS AT SECURITY-ALERT@HP.COM WERE NOT OF HELP. &lt;BR /&gt;HAS ANY BODY SEEN THIS?  &lt;BR /&gt;</description>
    <pubDate>Fri, 17 Nov 2000 14:47:55 GMT</pubDate>
    <dc:creator>CHRIS_ANORUO</dc:creator>
    <dc:date>2000-11-17T14:47:55Z</dc:date>
    <item>
      <title>Virus Attack or Have I been Hacked?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/virus-attack-or-have-i-been-hacked/m-p/2465366#M759948</link>
      <description>I CANN'T LOG INTO MY SERVER FROM ANY WHERE (INCLUDING CONSOLE), BOTH TELNET AND RLOGIN ARE NOT WORKING!&lt;BR /&gt;AND THE SYSTEM DISK ARE SHOWING BUSY BLINKING LIGHT, THE LCD HAS JUST F13F ON DISPLAY.&lt;BR /&gt;HOW CAN I GO INTO THE SERVER TO CHECK THE DIRECTORIES. SINCE CONSOLE LOGIN IS NO LONGER WORKING. WHEN I RUN 'HPUX LL' AT ISL&amp;gt;, IN SEE THAT ALL IDS IN /STAND WERE CHANGED TO USER AND GROUP ID NUMBERS. VMUNIX, SYSTEM AND THE *.PREV FILES ARE ALL ZERO. THEY GUYS AT SECURITY-ALERT@HP.COM WERE NOT OF HELP. &lt;BR /&gt;HAS ANY BODY SEEN THIS?  &lt;BR /&gt;</description>
      <pubDate>Fri, 17 Nov 2000 14:47:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/virus-attack-or-have-i-been-hacked/m-p/2465366#M759948</guid>
      <dc:creator>CHRIS_ANORUO</dc:creator>
      <dc:date>2000-11-17T14:47:55Z</dc:date>
    </item>
    <item>
      <title>Re: Virus Attack or Have I been Hacked?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/virus-attack-or-have-i-been-hacked/m-p/2465367#M759949</link>
      <description>No nothing like, perhaps on a AIx a have I couldnt do a mksysb the reason was a patch (or someone) did a diff of the directoy where the kernel was &amp;gt; the kernel...&lt;BR /&gt;I would try to recuperate by ftp if you can important config files like passwd hosts ...&lt;BR /&gt;onto pc or non HPUX system, to see if there is an explanation, again if ftp works, try to put a kernel, get rid of the resolver and try to boot as a stand alone machine then have a look inside...&lt;BR /&gt;I know its not much of an help for now, just think we are with you, keep in touch and if we have better ideas, we shall submit them...&lt;BR /&gt;All the best&lt;BR /&gt;Victor</description>
      <pubDate>Fri, 17 Nov 2000 15:02:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/virus-attack-or-have-i-been-hacked/m-p/2465367#M759949</guid>
      <dc:creator>Victor BERRIDGE</dc:creator>
      <dc:date>2000-11-17T15:02:01Z</dc:date>
    </item>
    <item>
      <title>Re: Virus Attack or Have I been Hacked?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/virus-attack-or-have-i-been-hacked/m-p/2465368#M759950</link>
      <description>I had the same probleme after a patch.&lt;BR /&gt;&lt;BR /&gt;rlogin didn't work but remsh YES&lt;BR /&gt;&lt;BR /&gt;Could you try something like this :&lt;BR /&gt;&lt;BR /&gt;remsh BADHOST -n "export DISPLAY=GOODHOST:0.0;xterm"&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;Patrice.&lt;BR /&gt;</description>
      <pubDate>Fri, 17 Nov 2000 15:13:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/virus-attack-or-have-i-been-hacked/m-p/2465368#M759950</guid>
      <dc:creator>MARTINACHE</dc:creator>
      <dc:date>2000-11-17T15:13:05Z</dc:date>
    </item>
    <item>
      <title>Re: Virus Attack or Have I been Hacked?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/virus-attack-or-have-i-been-hacked/m-p/2465369#M759951</link>
      <description>Chris&lt;BR /&gt;Is this situation after a reboot?&lt;BR /&gt;&lt;BR /&gt;It sounds like that the server loading has gone through the roof and processor time is not being given to telnet -etc.&lt;BR /&gt;&lt;BR /&gt;You have to my mind two options :-&lt;BR /&gt;1. Leave it and see if it gets better.&lt;BR /&gt;2. Hit the big red button (as I would do) bring it to a stand still - disconnect network/comms and reboot.&lt;BR /&gt;&lt;BR /&gt;Good luck&lt;BR /&gt;&lt;BR /&gt;Paula.</description>
      <pubDate>Fri, 17 Nov 2000 15:18:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/virus-attack-or-have-i-been-hacked/m-p/2465369#M759951</guid>
      <dc:creator>Paula J Frazer-Campbell</dc:creator>
      <dc:date>2000-11-17T15:18:34Z</dc:date>
    </item>
    <item>
      <title>Re: Virus Attack or Have I been Hacked?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/virus-attack-or-have-i-been-hacked/m-p/2465370#M759952</link>
      <description>Thanks, Actually this problem happened on 14/11/2000 and I had the system up and running in 2hrs. I recovered with the IUX recovery tape and updated with the lattest backup. I just wanted to know if anybody have had a similar experience. Lesson is - have a good recovery media and updated backups.&lt;BR /&gt;&lt;BR /&gt;Thanks</description>
      <pubDate>Fri, 17 Nov 2000 15:25:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/virus-attack-or-have-i-been-hacked/m-p/2465370#M759952</guid>
      <dc:creator>CHRIS_ANORUO</dc:creator>
      <dc:date>2000-11-17T15:25:57Z</dc:date>
    </item>
    <item>
      <title>Re: Virus Attack or Have I been Hacked?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/virus-attack-or-have-i-been-hacked/m-p/2465371#M759953</link>
      <description>Thanks, Actually this problem happened on 14/11/2000 and I had the system up and running in 4hrs. I recovered with the IUX recovery tape and updated with the lattest backup. I just wanted to know if anybody have had a similar experience. Lesson is - have a good recovery media and updated backups.&lt;BR /&gt;&lt;BR /&gt;Thanks</description>
      <pubDate>Fri, 17 Nov 2000 15:29:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/virus-attack-or-have-i-been-hacked/m-p/2465371#M759953</guid>
      <dc:creator>CHRIS_ANORUO</dc:creator>
      <dc:date>2000-11-17T15:29:59Z</dc:date>
    </item>
    <item>
      <title>Re: Virus Attack or Have I been Hacked?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/virus-attack-or-have-i-been-hacked/m-p/2465372#M759954</link>
      <description>I am not surprised that you saw ownership of the files in /stand as a UID of 0.  That is normal.  Since you were at the ISL (?) prompt, /etc had not been mounted yet, hence no resolution of UID/GID to their normal names.&lt;BR /&gt;&lt;BR /&gt;All files ownership and group properties are stored as the numeric UID/GID number.  When you do an ll when the system is running normally, the UID/GID numbers get converted automatically to their normal names.&lt;BR /&gt;&lt;BR /&gt;The UID of 0, which you saw in /stand is the UID for the root user.  All of /stand should be owned by root.</description>
      <pubDate>Fri, 17 Nov 2000 15:33:18 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/virus-attack-or-have-i-been-hacked/m-p/2465372#M759954</guid>
      <dc:creator>Patrick Wallek</dc:creator>
      <dc:date>2000-11-17T15:33:18Z</dc:date>
    </item>
    <item>
      <title>Re: Virus Attack or Have I been Hacked?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/virus-attack-or-have-i-been-hacked/m-p/2465373#M759955</link>
      <description>All the /stand file sizes where zeroed.</description>
      <pubDate>Fri, 17 Nov 2000 15:44:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/virus-attack-or-have-i-been-hacked/m-p/2465373#M759955</guid>
      <dc:creator>CHRIS_ANORUO</dc:creator>
      <dc:date>2000-11-17T15:44:06Z</dc:date>
    </item>
  </channel>
</rss>

