Re: Possible Forum Update Today / Upcoming Downtime
its still completely unclear but from what I understand, there was a spanking new vulnerability discovered in the kernel of Fedora Core that he may have exploited. Other than tracing his steps and doing a massive review of the logs (and not finding anything concrete that shows his entry point), its like he magically walked into the server with a username + password and was able to upgrade that account to userid "0" (i.e. God Mode). Thankfully the system alerted me (I've setup certain triggers that, for obvious security reasons, I won't list) and was able to see exactly what he was doing and which accounts he compromised.
Then it was a matter of tightening the server, hardening it more, upgrading the kernel, shutting down even more ports bla bla bla bla.
The guy was pretty good cause he had forged his IP and I was unable to do a tracert, which is something I personally haven't experienced before. In most cases, even if the firewall / Machine has been disabled to respond to ping, you can at least run a partial traceroute to an IP and it ends a couple of hops before the target machine. But I was unable to even do that with his IP, which tells me it was forged. Running a GeoLocation on the IP indicated it was coming out of Saudi Arabia, which of course I imagine was nonsense.