First, a little background. I work for a small design firm in Carson City, Nevada. We do print and web design, basically anything marketing related. We host our clients on a server rented from Media Temple. The people I work for are not that savy when it comes to server maintainance, and they rely on another company to do basic sys admin stuff on the machine.
Well, it turns out that, 1) there was not firewall running. for the last year, 2) someone, expoloited it (of course) through some unsafe scripts that were running. Now our machine is being used as a spam relay (their words, not mine, I'm not too sure if that is correct terminology). Their recommendation is to start fresh, with a clean restore, which means we have to rebuild 100 hosting clients, and more importantly, thousands of email accounts. I refuse to believe that is our only option. But it looks like we have no choice.
Is there anything I can look for, maybe to track down the exploited scripts, or at least to stop the spam? We are already prepared to start fresh.
I put this in the RedHat forums as the media temple server is running redhat enterprise 3.
We are fscked aren't we?



