Random Number GodsRNG · Enemy Territory · Battlefield · D&D
Friday BF64 + Sunday D&D

Check the calendar. ET pubs running the new Frostbite rotation all week.

Someone guessed the password of a superuser on an Ubuntu server. How to make sure nothing malicious was installed?

Permalink Preview Print PC
lyublyutvoyumamu
Field Medic
Members
26 posts 22 Jun 2023 joined
7 Sep 2026 at 16:06 #1

The breech should be fixed now but is it possible to check for any DDoS malware installed on the server or some other malicious software? What are the recommended steps now short of reinstalling everything?

lyublyutvoyumamu - BF support
Ammo box is friendship.

lolich213623
Engineer
Members
44 posts 5 Oct 2018 joined
7 Sep 2026 at 16:09 #2

Honestly, reinstall everything.

And look into strong passwords.

lolich213623 - EU evenings
CET after work.

fgdxhdgxcvx
Engineer
Members
46 posts 14 Aug 2023 joined
7 Sep 2026 at 16:14 #3

You'd need to check every single file against known good files.

It would be quite the undertaking but it's posible in theory.

fgdxhdgxcvx - Old guard
Jaymod days. Still here.

cirno114514
Engineer
Members
37 posts 13 May 2020 joined
7 Sep 2026 at 16:16 #4

Maybe ClamAV and rkhunter? But I know nothing of servers..

cirno114514 - ET / smokes
Utility first.

O_pr1vet1337
Field Medic
Members
34 posts 27 Jan 2020 joined
7 Sep 2026 at 16:18 #5

In all honesty, they could have made so many things as a superuser that it'd probably be easier to reinstall, and most audit systems won't flag much besides "someone became root", I'd say check how attackers try to scout or exploit systems for attack, a lot of those steps apply in a very similar manner to finding how someone could have left a backdoor or such, e.g., checking systemd services, cron jobs, file permissions, setuid files, in your case also check files that were modified recently, if the kernel and secure boot weren't tampered with in any way, etc wtc.

O_pr1vet1337 - EU evenings
CET after work.

NesoOP
Covert Ops
Members
51 posts 17 Oct 2021 joined
7 Sep 2026 at 16:20 #6

If you do not have physical access, you can't guarantee that your check captures the true state of the server.

NesoOP - D&D nights
Nat 1s are character development.

fgdxhdgxcvx
Engineer
Members
46 posts 14 Aug 2023 joined
7 Sep 2026 at 16:22 #7

Yeah 100%, you need to do it directly on the machine.

Hopefully a potentially compromised machine is not allowed any network access.

fgdxhdgxcvx - Old guard
Jaymod days. Still here.

bogdan22877
Field Medic
Members
25 posts 15 Aug 2019 joined
7 Sep 2026 at 16:26 #8

The possibilities of what could have been done with a sudo password are endless, the only safe answer is back up only inert user data and wipe the rest and reinstall.

Was this done over ssh? If so you should be locking down port 22 to only certain privileged IPs via firewall, I do so in two layers, once at my router and again on the OS firewall, white-listing allowed IP addresses that I control.

Never allow ssh via PW, disable ssh as root, and allow ED25519 keys only in sshd config.

You can change the ssh port, and you can deploy fail2ban but I far prefer just denying aptempts in the first place,

Changing the port is just "security via obscurity" and is actually neither. Port 2222 is not nearly as clever as you think it is.

bogdan22877 - Map votes
Frostbite supremacy.

lyublyutvoyumamu
Field Medic
Members
26 posts 22 Jun 2023 joined
7 Sep 2026 at 16:29 #9

I'm not sure what you mean by disable root remote password login. We only access the server via ssh and then use sudo. Is that not normal?

Banning IPs based on failed attempts is a good idea. Is this something out of the box or do I need to install something to do this?

lyublyutvoyumamu - BF support
Ammo box is friendship.

O_pr1vet1337
Field Medic
Members
34 posts 27 Jan 2020 joined
7 Sep 2026 at 16:35 #10

Sorry, you said "someone guessed the superuser password" on the title, which implies someone logged in as root directly, if someone with sudo privileges had their account compromised that a very similar issue still.

I think IP banning was something the fail2ban package does, not sure if it is installed or set up by default on Ubuntu server.

O_pr1vet1337 - EU evenings
CET after work.

lyublyutvoyumamu
Field Medic
Members
26 posts 22 Jun 2023 joined
7 Sep 2026 at 16:37 #11

Aren't users with sudo rights called superusers?

lyublyutvoyumamu - BF support
Ammo box is friendship.

BienDoncarlo
Field Medic
Members
32 posts 5 Oct 2025 joined
7 Sep 2026 at 16:37 #12

For a start use ssh keys to login.

BienDoncarlo - EU evenings
CET after work.

O_pr1vet1337
Field Medic
Members
34 posts 27 Jan 2020 joined
7 Sep 2026 at 16:37 #13

Yeah, a quick nmap or just guessing common alternative ports can catch it.

O_pr1vet1337 - EU evenings
CET after work.

Sign in to reply.