Hacker in Cairo.
10 December 2005
I woke up earlier this morning without an alarm set than I've been waking up on a lot of recent weekday mornings. Which I was trying to decide if I should actually get out of bed or bury my head back under the covers and try to get some more sleep, my phone beeped, a message from George, letting me know that although he could get shell access to avocado, the web server seemed to be down.
I figured that I should check it out, but before I could do much poking around (there didn't seem to be any runaway processes or anything) my shell stopped responding. Since it's earlier in Austin, where avocado still resides, I decided that I'd wait a bit and see if it righted itself before bothering the tech guy on a Saturday morning. I know that it's his job that he's getting paid for, but I do try to thing about what I would want in his place.
So I took a shower. Went to brunch. Bought a thermal t-shirt and some new underwear push back the need to do laundry another few days. Stopped by the Strand where I was overwhelmed by the crowd of holiday shoppers. And then went into work where I checked avocado again and found her to be running normally, with the exception of the web and mail servers that don't come up automagically after a reboot.
It seems that someone in Cairo spent a few hours last night trying to hack into various system accounts through ssh, unsuccessfully. And that a few hours after that, avocado rebooted. It seems like a big coincidence for the two things to not be related, but possible that they aren't. Then, after the reboot, there was a period of time where the net connection went up and down about fifteen times. From the logs it looks like it was an outside problem, as if the cable were being physically pulled and plugged back in, or that the router was having power fluctuations. But, this happened during the same time that the web server was trying to start up (which it can't do on its own without the secure server passphrase), and may have been tied to that.
In any case, I got things back online, and will be keeping a close eye on the logs over the next few days.