Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
The hack of my gentoo today
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
Boris Kavod
Tux's lil' helper
Tux's lil' helper


Joined: 13 Jan 2004
Posts: 81
Location: Colombes (France - 92)

PostPosted: Thu Jun 09, 2005 9:44 pm    Post subject: The hack of my gentoo today Reply with quote

(sorry for my bad English : I'm French)

I would like to share my experience of hack of today.

(P.S. : all the system strings are approximate ones. I saved logs but I'm reinstall my system so I can't see them)

My server "was" a Gentoo which haven't been updated from one or two month (yes, it's baaaad).

I'm behind a gateway with IPCop distribution (http://www.ipcop.org).

My server had several ports opened (FTP, SSH, HTTP and HTTPS).

Near 6H AM, my server was down but I saw it only at 10H AM without be able to do anythings (because at work).

When I came back, I saw differents problem :
"cat" was returning a seg fault
every services turned down
when I wanted to turn them up, I was said "only root can turn services up" (but I was root)
reboot didn't work

When I reseted, /bin/rc crashed.

I used a knoppix and chroot on my root HD. I did a ls and I see :
"entering to promiscuous mode"
So, I did a netstat which show me a connection to an unknown adress port 80 and from the ls process.

So, I unpluged the ethernet cable and I started a reinstall ;)

after seeing my logs, I think it's apache which was the door.

If anyone is interresting, I can share my logs when I'll find them again.
Back to top
View user's profile Send private message
keli
Apprentice
Apprentice


Joined: 18 Jul 2003
Posts: 210
Location: TgMures, RO

PostPosted: Thu Jun 09, 2005 10:52 pm    Post subject: Reply with quote

Probably not apache itself was the doorway, but rather some long time expired public web application, that might have been hosted there.

We have been broken into recently through an ancient awstats.cgi

There are a bunch of exploits for various web applications running over apache, that are easily exploitable.

Anyway, if you've found it out right away, than it was an amature. ;)
_________________
"The future masters of technology will have to be lighthearted and intelligent. The machine easily masters the grim and the dumb."
Marshall McLuhan, 1969
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum