my deb server got hacked, little help?
Hello all.
I got debian server which was haxed today. (Wondered why it lagged and checked auth.log and noticed that german ip had logged in as root which should be impossible because no one else has access to server than me).
It´s Linux 2.2.20-compact.
I had run apt-get update and apt-get dist-upgrade yesterday so everything should be up to date.
So I ran chkrootkit. Nothing critical came up.
I checked roots bash history, nothing.
Then i unplugged it from internet.
I´d like to know:
1. How to see how that hacker got in/got my root pass?
2.How to see what he did when he was inside?
3.What i should do before reinstalling?
Thx for all who answer.
<Lorvija>