
PCI Compliance Scanning & SAQ
Making compliance easy...
| Sign up now and get your SAQ compliance certificate online quickly and easily for your merchant bank. | Sign up now for both the SAQ Compliance certificate and your PCI Scan Compliance certificate. |
|
![]() |
If your Server is Compromised Can it be Repaired or Should it be Rebuilt?
Servers are one of the most important pieces of hardware for companies that do business on the internet. Often, these servers store personal and financial information of current customers. This makes them a prime target of internet thieves who make their living breaking into servers and stealing information. How can you tell that your server has been hacked?
For a thief to gain access to your system, he must use either a virus or a worm. These programs typically disrupt the normal functions of your computer, which often manifests itself in a general slowdown of operations or intermittent freezes.
If your computer demonstrates any of the common computer virus systems, it is important that you investigate right away. Begin by checking the log record. Are they multiple login attempts by users that you do not recognise? If there are, it may mean that your server has been compromised. Hackers may also create new user accounts, add .exe files, or disable the anti-virus.
What next? If you are reasonably certain that your server has been compromised, disconnect it from the network immediately. Then make a copy of all important data and log files onto a removable hard drive. Take note of any missing files, programs or accounts.
Once your data has been saved, you can begin the investigation. Start with the MySQL logs. Look for anything that stands out. Check the server logs next and see if you can identify the new user accounts that the hacker created and the addresses they used to log on. This information can be given to the proper authorities and may result in criminal prosecution.
Lastly, wipe the server clean. Reinstall all of the necessary programs and install the data from the removable hard drive. Once everything is up and running check to see that your anti-virus software is current. More often than not, a simple mistake like forgetting to update protective software is how thieves are able to gain access to your system.

