by tachzusamm » Tue Oct 13, 2009 5:31 am
Just in case you are wondering - or missing the texturu service - I sadly have to inform you that the account has been currently disabled.
This happened because the provider got an abuse mail, telling that there was a DoS attack initiated from the texturu server to a different server (somewhere in romania), so they unplugged the connection.
Seems the server has been compromised (hacked).
I can request to reactivate the server again, but I'm hesitating because I want to know first what exactly is the best procedure to detect whats happening when the machine is running again (sort of listing running processes, detecting outgoing traffic and such) and I want to be sure to know how I can disable the malicious activity.
Really sorry guys.
(If anyone has experiences with detecting/identifying unwanted processes, or blocking unintended outgoing traffic via iptables or whatever, additional advice is greatly appreciated.)