We have a mid-size business template on public ip-addresses behind a firewall, the problem was that we had the default passwords over a weekend before we changed them, and now our firewall's cpu was working at a 100% beacuse one of the servers was scanning the net. We have blocked the port that the mbt is using for the scans but the problem is still there. A friend that know linux a little better told me that this could indicate root-kit, im not sure if that was the problem or the solution to the problem,,,???
Any ideas?
Should we do backups and reinstall everything...???
Any ideas?
Should we do backups and reinstall everything...???