Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
i was hacked little help plz?
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
dbzeath
n00b
n00b


Joined: 01 Jul 2004
Posts: 15

PostPosted: Thu Oct 14, 2004 5:28 pm    Post subject: i was hacked little help plz? Reply with quote

one of my user accounts at least was hacked the problem i'm having is i can't see anything in any log files i'm running metalog they attacker/s created files in my ~/.xchat2/xchatlogs/ folder like

bash-2.05b# ls -ln /home/death/.xchat2/xchatlogs/
total 108
-rw-r--r-- 1 1000 100 0 Oct 13 18:55 203.59.30.93?
-rw-r--r-- 1 1000 100 0 Oct 13 18:56 ??
-rw-r--r-- 1 1000 100 235 Oct 15 01:03 AustNet-#chatterz.log
-rw-r--r-- 1 1000 100 435 Oct 15 01:03 AustNet-#comrads.log
-rw-r--r-- 1 1000 100 23590 Oct 15 01:25 AustNet-#perth.log
-rw-r--r-- 1 1000 100 596 Oct 15 01:20 AustNet-#perthdc.log
-rw-r--r-- 1 1000 100 3674 Oct 15 01:22 AustNet-#snz.log
-rw-r--r-- 1 1000 100 4133 Oct 15 01:20 AustNet-#w.a.log
-rw-r--r-- 1 1000 100 400 Oct 15 01:03 AustNet-#wa.log
-rw-r--r-- 1 1000 100 3051 Oct 15 01:25 AustNet-#wb.log
-rw-r--r-- 1 1000 100 4692 Oct 15 01:04 AustNet-austnet.log
-rw-r--r-- 1 1000 100 0 Oct 14 17:50 You
-rw-r--r-- 1 1000 100 0 Oct 13 18:55 ahah?
drwxr-xr-t 2 1000 100 12704 Oct 15 01:02 back
-rw-r--r-- 1 1000 100 0 Oct 13 18:55 hhggst089?
-rw-r--r-- 1 1000 100 2411 Oct 15 01:25 irc.freenode.net-#gentoo-amd64.log
-rw-r--r-- 1 1000 100 16139 Oct 15 01:25 irc.freenode.net-#gentoo.log
-rw-r--r-- 1 1000 100 3785 Oct 15 01:03 irc.freenode.net-irc.freenode.net.log
-rw-r--r-- 1 1000 100 695 Oct 15 01:20 irc2.waixreactor.net-#wb.log
-rw-r--r-- 1 1000 100 1837 Oct 15 01:03 irc2.waixreactor.net-irc2.waixreactor.
net.log
-rw-r--r-- 1 1000 100 0 Oct 13 18:55 it

i believe it is quite obvious what files belong and what don't could someone plz help me track down this person? that folder is the only place that i can see that has been altered

EDIT AFAIK they didn't get any root access
Back to top
View user's profile Send private message
xbmodder
Guru
Guru


Joined: 25 Feb 2004
Posts: 404

PostPosted: Thu Oct 14, 2004 5:49 pm    Post subject: Reply with quote

remove the user, rm -rf /home/death, add user back, set pass yourdeadifyoucrackthis
Back to top
View user's profile Send private message
daemonflower
Apprentice
Apprentice


Joined: 17 Jul 2004
Posts: 290

PostPosted: Thu Oct 14, 2004 5:56 pm    Post subject: Reply with quote

In addition, better check whether any files have been modified in /etc, and in /bin and /usr/bin as well. And at least I can find logins in /var/log/messages, maybe you find a clue there from where you were cracked.
Back to top
View user's profile Send private message
econan
n00b
n00b


Joined: 01 Oct 2003
Posts: 17
Location: Washington, DC

PostPosted: Thu Oct 14, 2004 6:40 pm    Post subject: Reply with quote

Try to find out why you were hacked and learn from that mistake. Do not repeat it again.

Also check if the cracker got root access and potentially put a rootkit to the system. Immediately remove the system from the network if you haven't done so. Get a knoppix like live CD and start investigating for possible rootkits. A good start would be STD Knoppix [http://www.knoppix-std.org/] I don't know how updated it is in STD but you can download the utility chkrootkit [http://www.chkrootkit.org/] for further rootkit investigations.

While making your investigations do not forget to mount your hard drive partition(s) read only.

Also if you do not have a critical information on that computer, i'd highly suggest to wipe it out and reinstall the OS. If not, if you are making backups, use a known non cracked backup version.

Good Luck.
Back to top
View user's profile Send private message
KozmoNaut
Apprentice
Apprentice


Joined: 09 Dec 2002
Posts: 168
Location: Denmark

PostPosted: Thu Oct 14, 2004 6:56 pm    Post subject: Reply with quote

In addition to chkrootkit, try rkhunter. It never hurts to check twice ;)
_________________
War. War never changes.
Back to top
View user's profile Send private message
ikaro
Advocate
Advocate


Joined: 14 Jul 2003
Posts: 2527
Location: Denmark

PostPosted: Thu Oct 14, 2004 7:48 pm    Post subject: Reply with quote

yeah and if your modem blinks, then its because they are still in ..
_________________
linux: #232767
Back to top
View user's profile Send private message
lousyd
Apprentice
Apprentice


Joined: 15 Mar 2003
Posts: 166
Location: Des Moines

PostPosted: Fri Oct 15, 2004 12:21 am    Post subject: Reply with quote

chkrootkit tells me:
Code:
Checking `du'... INFECTED
Checking `find'... INFECTED
Checking `init'... INFECTED
Checking `ls'... INFECTED
Checking `netstat'... INFECTED

rkhunter tells me that everything is cool, including the above programs. This sounds to me like maybe chkrootkit is wrong. How likely is this? I re-emerged coreutils, and I still get the above. Perhaps gcc itself is infected and is compiling coreutils with the infections...

Oh, and my modem is blinking. I think it's because I visited Slashdot and so some hackers found out about my system.
_________________
Minds are like parachutes... Most people will do their damnedest to avoid having to use one.
Back to top
View user's profile Send private message
xbmodder
Guru
Guru


Joined: 25 Feb 2004
Posts: 404

PostPosted: Fri Oct 15, 2004 3:23 am    Post subject: Reply with quote

wow i never knew linux could get a virus...
emerge clamav
edit you /etc/clamd.conf remove the example line
/etc/init.d/clamd start
clamd PING #(make sure this works)
freshclam
/etc/init.d/clamd restart
cd /
clamscan -r
EDIT
9:-clamscan
9:+clamscan -r
Back to top
View user's profile Send private message
daemonflower
Apprentice
Apprentice


Joined: 17 Jul 2004
Posts: 290

PostPosted: Fri Oct 15, 2004 10:50 am    Post subject: Reply with quote

lousyd wrote:
This sounds to me like maybe chkrootkit is wrong. How likely is this?
I don't know how likely this is, but i don't get positives on those files here. chkrootkit-0.44, coreutils-5.2.1.
Back to top
View user's profile Send private message
xbmodder
Guru
Guru


Joined: 25 Feb 2004
Posts: 404

PostPosted: Fri Oct 15, 2004 1:55 pm    Post subject: Reply with quote

PING!!!!!!!!!11
listen to me clamav is never wrong.!!!!!!!!!!!
if ya want you can get a new set of glibc + gcc + binutils +coreutils
Back to top
View user's profile Send private message
ikaro
Advocate
Advocate


Joined: 14 Jul 2003
Posts: 2527
Location: Denmark

PostPosted: Fri Oct 15, 2004 2:30 pm    Post subject: Reply with quote

I think your motherboard bios is infected with a trojan!

you should install another hard drive and switch your mouse ASAP!

spamware is very dangerous and if you use Internet explorer makes sure to disable cakes.
_________________
linux: #232767
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum