Re: [Jack-Devel] www.jackaudio.org defacement
On Sat, Dec 31, 2011 at 12:04:52AM -0600, David Nielson wrote:
> Paul, I would suggest moving to a better-managed hosting service.
For my own web sites I hire a bare-bones unmanaged VPS that only
came with a Linux base installation plus ssh login. I remotely installed
and configured all the web and mail server software myself, just so I
would have full control over the setup. I'm still at the mercy of the
ISP's VPS host security setup of course, but at least being in control
of the VPS itself gives me some peace of mind.
Paul, have you checked the ssh logs (assuming you have access) for
anything unusual? My own ssh server is subject to a constant onslaught
of automated brute force attacks. I wouldn't consider running ssh without
serious firewall rules to block these attempts.
John
1325329811.16975_0.ltw:2,a <20111231111430.GA2571 at localhost0 dot localdomain>