Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Got hacked, "HASCH"
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
olman
n00b
n00b


Joined: 02 Mar 2005
Posts: 7

PostPosted: Wed Mar 02, 2005 4:58 pm    Post subject: Got hacked, "HASCH" Reply with quote

Today i noticed that I got hacked by a group or something named "(H)ackers (A)gainst (S)wedish (C)omputer (H)omos"
The funny is that I ran a update yesterday night (23:30 GMT+1), and today around 10:30 (GMT+1) it was hacked.

Its some kind of script that runs instead of bash when i log on. But its only two users hacked, my standard user and the root user. All other users can login normaly. I've set SSH to only get access to root via the user that got hacked. root cant login as ftp either (my settings).

Now when I've read some logfiles I cant find anything.. Something that made me thinking was that the hole apache2 log directory was empty (/var/log/apache2/) the SSH directory is also empty (/var/log/sshd/). I've found one file at roots home that was named "sorryy" but it didnt contain anything. I'm just intressted in what you pepole think that this hacker did, and what way they got in.

Sorry for my bad english.
Back to top
View user's profile Send private message
BitJam
Advocate
Advocate


Joined: 12 Aug 2003
Posts: 2513
Location: Silver City, NM

PostPosted: Wed Mar 02, 2005 5:35 pm    Post subject: Reply with quote

First, I think a re-install is in order. Any data or files you created yourself should be safe. But it is possible (if not likely) that the crackers still have control of your box.

Second, the easiest thing to do to find out what they've done is to emerge chkrootkit and run it. But for safety sake, you should probably boot from the LiveCD and do the chroot trick from the install instructions to access your machine until you've determined for sure that it is clean.
Back to top
View user's profile Send private message
olman
n00b
n00b


Joined: 02 Mar 2005
Posts: 7

PostPosted: Wed Mar 02, 2005 5:39 pm    Post subject: Reply with quote

Yeah, Thats what I've done. No network connection and have booted up from the livecd to even could get access to the logfiles. Nothing strange with the .bashrc and so on. A reinstall is going to be made but I wanted to check logfiles and so first. :)
Back to top
View user's profile Send private message
BitJam
Advocate
Advocate


Joined: 12 Aug 2003
Posts: 2513
Location: Silver City, NM

PostPosted: Wed Mar 02, 2005 5:56 pm    Post subject: Reply with quote

chkrootkit?
Back to top
View user's profile Send private message
olman
n00b
n00b


Joined: 02 Mar 2005
Posts: 7

PostPosted: Wed Mar 02, 2005 6:06 pm    Post subject: Reply with quote

I've booted up the livecd and mounted the system and then i chrooted into the partion that i mounted. Thats all.
Back to top
View user's profile Send private message
Jayso
n00b
n00b


Joined: 02 Jul 2003
Posts: 21

PostPosted: Wed Mar 02, 2005 10:51 pm    Post subject: Reply with quote

out of curiosity....were you running php or any website running php?
what are the top few lines of `last` ?
there could be a number of ways they got in, usually php websites, phpbb phpnuke etc those kinda things have holes
and if they arent patched then you might as well tell someone your root pw.
what commands did they run if any? (.bash_history)
if they seemed to have cleaned very well, then most likely they had a script run to do it for them.
Also, check /tmp or /var/tmp
sometimes you find some funny things in there.... lots of times its nothing though..
but emerge chkrootkit would probably be a good idea if you want to check anything else out,
however a fresh install is probably good.
Back to top
View user's profile Send private message
Sith_Happens
Veteran
Veteran


Joined: 15 Dec 2004
Posts: 1807
Location: The University of Maryland at College Park

PostPosted: Wed Mar 02, 2005 11:03 pm    Post subject: Reply with quote

But he said he updated on tuesday night, and was hacked after that. If he was using phpBB then he would have the patched version, sans security holes. I think it was put into portage on monday.
_________________
"That question was less stupid; though you asked it in a profoundly stupid way."
I'm the brains behind Jackass! | Tutorials: Shorewall
Back to top
View user's profile Send private message
olman
n00b
n00b


Joined: 02 Mar 2005
Posts: 7

PostPosted: Thu Mar 03, 2005 8:06 am    Post subject: Reply with quote

Yeah, like Sith_Happens said, i updatede the night before. I didnt run any kind of forum. I had php5.0.3, apache2 and mysql. Nothing strange is displayed in .bash_history now I've startade a reinstall and will be thinking of more security. Mabye the were getting in from my mysql querys. Will make they more secure next time. :P
Back to top
View user's profile Send private message
F.Ultra
Apprentice
Apprentice


Joined: 17 Mar 2004
Posts: 169
Location: Sweden

PostPosted: Thu Mar 03, 2005 9:33 am    Post subject: Reply with quote

Or do you accept SSH connectsions from anywhere and have a root password that is easy to guess/crack ?
Back to top
View user's profile Send private message
schiotz
Apprentice
Apprentice


Joined: 20 Jan 2004
Posts: 206
Location: Denmark

PostPosted: Thu Mar 03, 2005 11:02 am    Post subject: Reply with quote

olman wrote:
I've booted up the livecd and mounted the system and then i chrooted into the partion that i mounted. Thats all.


Try running chrootkit (not chroot!) to check if somebody installed a rootkit.

Do you use the same password on another machine (work, university, ....). In that case, perhaps that machine got hacked and your password was cracked. Then the hacker can see in the logs that you often log in from your own machine, and try the same password there.
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum