By franx47
Hi,
I want to ask something about server that has been compromised. Recently, one of my VPS server has been hacked and the attacker install somekind like “IRC” script.
Everytime I killed the process or close the port, it can open again .. and again ..I’m sure the attacker has installed something like a hidden script. I hv using tool like Rootkit Hunter and find each of the suspicious result.
It really makes me crazy and pain. How can he/she go into my server (as a root) even I have changed the root password.
OS: Centos 5.
Please help. 🙁