[CentOS] data recovery

Keith Roberts keith at karsites.net
Fri Sep 23 18:32:03 UTC 2011


On Fri, 23 Sep 2011, Paras pradhan wrote:
*snip*

> No. This is a production server and nobody logs in. Very 
> very restricted.

Have you checked all your logs? What ports are open?
What CLI tools to format a HDD do you have on the server?

>
>>
>> Also, is it possible for a trojan program to do this to your
>> HDD?
>
> Are there any know trojan that can change the disk layout?

I don't know of any. What applications do you have running 
on that server?

You say a production server. What type of server - a web 
hosting provider?

What scripting languages do you have running on the server, 
if any?

If you give me an email directly, I might be able to do a 
remote login for you, and some forensics, as that is one of 
my many interests.

Kind Regards,

Keith Roberts

-----------------------------------------------------------------
Websites:
http://www.karsites.net
http://www.php-debuggers.net
http://www.raised-from-the-dead.org.uk

All email addresses are challenge-response protected with
TMDA [http://tmda.net]
-----------------------------------------------------------------



More information about the CentOS mailing list