How to regain use of server after intrusion.

0

I had an intrusion on my server ... a password was brute forced by some kid who proceeded to use the box to try to brute force other boxes.

I found and removed the script that was doing this, and secured the box ... but AWS has embargoed my server, leaving only the ssh port and one other open. This renders the system useless for doing my work.

I have no idea how to contact them to let them know what happened and hopefully regain my ability to use the system.

Please advise!

질문됨 일 년 전187회 조회
1개 답변
0

Are you trying to regain the SSH access? If yes, please follow the below methods mentioned in the link: https://aws.amazon.com/premiumsupport/knowledge-center/user-data-replace-key-pair-ec2/ I hope this will help!

profile pictureAWS
답변함 일 년 전
  • I have ssh access. They left port 22 up, and they left one other port in the 3 thousands open.

    But they are blocking https, http, and everything else. So my applet cannot talk to it's server, which it does over https.

    I made a snapshot and brought up another server, but it was completely unreachable, so I deleted it.

    There is no indication that they intend to allow me to access the resources that my organization is paying for ever again. I hope that i is not the case, but they have given me no clue as to how to contact them.

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠