I have a Linux server which is compromised, I can see nasty looking perl scripts executing with root privileges. I want to get some data off it before I wipe it. How can I block all inbound and outbound traffic except for my ip? It's a Centos server I assume i can do this with iptables?
I'm aware a the server is rooted there is a possibility that attackers could have made changes on the server that would prevent this from working. Ill be testing to make sure and only have the server online for a couple of hours before it is nuked.
iptableshas been affected. You should physically disconnect the machine from the network, and grab any data you need from the compromised host using either a crossover cable or a USB stick. – voretaq7 Jul 01 '13 at 16:57