View previous topic :: View next topic |
Author |
Message |
dbzeath n00b
![n00b n00b](/images/ranks/rank_rect_0.gif)
Joined: 01 Jul 2004 Posts: 15
|
Posted: Thu Oct 14, 2004 5:28 pm Post subject: i was hacked little help plz? |
|
|
one of my user accounts at least was hacked the problem i'm having is i can't see anything in any log files i'm running metalog they attacker/s created files in my ~/.xchat2/xchatlogs/ folder like
bash-2.05b# ls -ln /home/death/.xchat2/xchatlogs/
total 108
-rw-r--r-- 1 1000 100 0 Oct 13 18:55 203.59.30.93?
-rw-r--r-- 1 1000 100 0 Oct 13 18:56 ??
-rw-r--r-- 1 1000 100 235 Oct 15 01:03 AustNet-#chatterz.log
-rw-r--r-- 1 1000 100 435 Oct 15 01:03 AustNet-#comrads.log
-rw-r--r-- 1 1000 100 23590 Oct 15 01:25 AustNet-#perth.log
-rw-r--r-- 1 1000 100 596 Oct 15 01:20 AustNet-#perthdc.log
-rw-r--r-- 1 1000 100 3674 Oct 15 01:22 AustNet-#snz.log
-rw-r--r-- 1 1000 100 4133 Oct 15 01:20 AustNet-#w.a.log
-rw-r--r-- 1 1000 100 400 Oct 15 01:03 AustNet-#wa.log
-rw-r--r-- 1 1000 100 3051 Oct 15 01:25 AustNet-#wb.log
-rw-r--r-- 1 1000 100 4692 Oct 15 01:04 AustNet-austnet.log
-rw-r--r-- 1 1000 100 0 Oct 14 17:50 You
-rw-r--r-- 1 1000 100 0 Oct 13 18:55 ahah?
drwxr-xr-t 2 1000 100 12704 Oct 15 01:02 back
-rw-r--r-- 1 1000 100 0 Oct 13 18:55 hhggst089?
-rw-r--r-- 1 1000 100 2411 Oct 15 01:25 irc.freenode.net-#gentoo-amd64.log
-rw-r--r-- 1 1000 100 16139 Oct 15 01:25 irc.freenode.net-#gentoo.log
-rw-r--r-- 1 1000 100 3785 Oct 15 01:03 irc.freenode.net-irc.freenode.net.log
-rw-r--r-- 1 1000 100 695 Oct 15 01:20 irc2.waixreactor.net-#wb.log
-rw-r--r-- 1 1000 100 1837 Oct 15 01:03 irc2.waixreactor.net-irc2.waixreactor.
net.log
-rw-r--r-- 1 1000 100 0 Oct 13 18:55 it
i believe it is quite obvious what files belong and what don't could someone plz help me track down this person? that folder is the only place that i can see that has been altered
EDIT AFAIK they didn't get any root access |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
xbmodder Guru
![Guru Guru](/images/ranks/rank_rect_3.gif)
Joined: 25 Feb 2004 Posts: 404
|
Posted: Thu Oct 14, 2004 5:49 pm Post subject: |
|
|
remove the user, rm -rf /home/death, add user back, set pass yourdeadifyoucrackthis |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
daemonflower Apprentice
![Apprentice Apprentice](/images/ranks/rank_rect_2.gif)
![](images/avatars/13506633894146d4b1d8de3.jpg)
Joined: 17 Jul 2004 Posts: 290
|
Posted: Thu Oct 14, 2004 5:56 pm Post subject: |
|
|
In addition, better check whether any files have been modified in /etc, and in /bin and /usr/bin as well. And at least I can find logins in /var/log/messages, maybe you find a clue there from where you were cracked. |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
econan n00b
![n00b n00b](/images/ranks/rank_rect_0.gif)
Joined: 01 Oct 2003 Posts: 17 Location: Washington, DC
|
Posted: Thu Oct 14, 2004 6:40 pm Post subject: |
|
|
Try to find out why you were hacked and learn from that mistake. Do not repeat it again.
Also check if the cracker got root access and potentially put a rootkit to the system. Immediately remove the system from the network if you haven't done so. Get a knoppix like live CD and start investigating for possible rootkits. A good start would be STD Knoppix [http://www.knoppix-std.org/] I don't know how updated it is in STD but you can download the utility chkrootkit [http://www.chkrootkit.org/] for further rootkit investigations.
While making your investigations do not forget to mount your hard drive partition(s) read only.
Also if you do not have a critical information on that computer, i'd highly suggest to wipe it out and reinstall the OS. If not, if you are making backups, use a known non cracked backup version.
Good Luck. |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
KozmoNaut Apprentice
![Apprentice Apprentice](/images/ranks/rank_rect_2.gif)
![](images/avatars/1335744575416c4515f0668.gif)
Joined: 09 Dec 2002 Posts: 168 Location: Denmark
|
Posted: Thu Oct 14, 2004 6:56 pm Post subject: |
|
|
In addition to chkrootkit, try rkhunter. It never hurts to check twice ![Wink ;)](images/smiles/icon_wink.gif) _________________ War. War never changes. |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
ikaro Advocate
![Advocate Advocate](/images/ranks/rank-G-1-advocate.gif)
![](images/avatars/130830920042dd3d4464379.jpg)
Joined: 14 Jul 2003 Posts: 2527 Location: Denmark
|
Posted: Thu Oct 14, 2004 7:48 pm Post subject: |
|
|
yeah and if your modem blinks, then its because they are still in .. _________________ linux: #232767 |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
lousyd Apprentice
![Apprentice Apprentice](/images/ranks/rank_rect_2.gif)
![](images/avatars/20847067913ec44e83df363.gif)
Joined: 15 Mar 2003 Posts: 166 Location: Des Moines
|
Posted: Fri Oct 15, 2004 12:21 am Post subject: |
|
|
chkrootkit tells me:
Code: | Checking `du'... INFECTED
Checking `find'... INFECTED
Checking `init'... INFECTED
Checking `ls'... INFECTED
Checking `netstat'... INFECTED |
rkhunter tells me that everything is cool, including the above programs. This sounds to me like maybe chkrootkit is wrong. How likely is this? I re-emerged coreutils, and I still get the above. Perhaps gcc itself is infected and is compiling coreutils with the infections...
Oh, and my modem is blinking. I think it's because I visited Slashdot and so some hackers found out about my system. _________________ Minds are like parachutes... Most people will do their damnedest to avoid having to use one. |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
xbmodder Guru
![Guru Guru](/images/ranks/rank_rect_3.gif)
Joined: 25 Feb 2004 Posts: 404
|
Posted: Fri Oct 15, 2004 3:23 am Post subject: |
|
|
wow i never knew linux could get a virus...
emerge clamav
edit you /etc/clamd.conf remove the example line
/etc/init.d/clamd start
clamd PING #(make sure this works)
freshclam
/etc/init.d/clamd restart
cd /
clamscan -r
EDIT
9:-clamscan
9:+clamscan -r |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
daemonflower Apprentice
![Apprentice Apprentice](/images/ranks/rank_rect_2.gif)
![](images/avatars/13506633894146d4b1d8de3.jpg)
Joined: 17 Jul 2004 Posts: 290
|
Posted: Fri Oct 15, 2004 10:50 am Post subject: |
|
|
lousyd wrote: | This sounds to me like maybe chkrootkit is wrong. How likely is this? | I don't know how likely this is, but i don't get positives on those files here. chkrootkit-0.44, coreutils-5.2.1. |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
xbmodder Guru
![Guru Guru](/images/ranks/rank_rect_3.gif)
Joined: 25 Feb 2004 Posts: 404
|
Posted: Fri Oct 15, 2004 1:55 pm Post subject: |
|
|
PING!!!!!!!!!11
listen to me clamav is never wrong.!!!!!!!!!!!
if ya want you can get a new set of glibc + gcc + binutils +coreutils |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
ikaro Advocate
![Advocate Advocate](/images/ranks/rank-G-1-advocate.gif)
![](images/avatars/130830920042dd3d4464379.jpg)
Joined: 14 Jul 2003 Posts: 2527 Location: Denmark
|
Posted: Fri Oct 15, 2004 2:30 pm Post subject: |
|
|
I think your motherboard bios is infected with a trojan!
you should install another hard drive and switch your mouse ASAP!
spamware is very dangerous and if you use Internet explorer makes sure to disable cakes. _________________ linux: #232767 |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
|