Root password doesn't work, I think i've been hacked. How can I check?

asked 2017-12-15 21:57:44 -0500

Is there a way to changer the root password using sudo or forcing a password reset? Also installed programs are missing (rkhunter) and the logfiles for security pgms (denyhosts, ssh) are gone, or do not allow access as user 'sg' (only user acct installed during setup)

Rebuild from scratch is not a bfd since it's a new install from a couple days ago - would just like to find out what happened before I wipe all the evidence. I've rescued the '/var/log/messages' file and about to parse it into a spreadsheet in Windoze to find out if any remote logins, etc

Thanks in advance

answered 2017-12-16 01:37:56 -0500

If this is the password you've forgotten, then here's how to reset it:

Reboot the machine
After the power on self-test screen, press and hold the Shift key
When the Grub boot menu comes up, select to boot in Recovery Mode.
At the Recovery Mode menu, choose to drop to a root shell.
At the prompt, type:

passwd your-user-name

Obviously replace your-user-name with your Ubuntu username.

Choose a new password
Reboot the PC.
