Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Probably rootkitted need help with diag & repair
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
WxY
n00b
n00b


Joined: 25 Apr 2011
Posts: 16

PostPosted: Mon Jan 09, 2012 10:51 am    Post subject: Probably rootkitted need help with diag & repair Reply with quote

Hey. I think my web facing router machine has been compromised. Anyways, I haven't removed any viruses/rootkits from a gentoo machine before so excuse me if I sound stupid.

What I found out so far:
The machine seems to be downloading a lot and only leaves 2 KiB +/- 0.5KiB for all of its clients. Funny enough though, my up link can do 2MiB/s but it only seems to drain 60KiB/s based on what I can read from watch --interval=1 ifconfig.

I made an educated guess with how best to approach the problem. I booted into runlevel 2, rebuilt my kernel & modules, remerged world but that didn't do the trick. So I'm guessing its probably a rogue kernel module that's biting me.

I'm trying to get rkhunter a go but its a bit difficult to get it when the machine that needs it can't really download anything and I don't really have a usb stick to transfer the tar balls over.

Any advise would be appreciated
Back to top
View user's profile Send private message
Bones McCracker
Veteran
Veteran


Joined: 14 Mar 2006
Posts: 1611
Location: U.S.A.

PostPosted: Mon Jan 09, 2012 12:46 pm    Post subject: Reply with quote

You'll probably get better advice, but this is what I'd do. By the time you get done screwing around with other approaches, this will probably have been less work.

First of all, make sure it's actually your router that's compromised and not one of your clients (see if the excess traffic is going through the input chain or the forward chain). A router, properly configured, ought to be the hardest machine on your network to compromise.

If it's indeed the router, unplug everything, pop in system rescue CD, obliterate the contents of the disk, including MBR, with dd, repartition, re-flash the BIOS, reinstall your software, and go.

You can safely back up all your config files (text) to speed re-installation.

Hopefully you'll get better advice. I'm not very smart. But that's what I'd actually do, and I'm not afraid to admit it. :lol:
_________________
patrix_neo wrote:
The human thought: I cannot win.
The ratbrain in me : I can only go forward and that's it.
Back to top
View user's profile Send private message
tomk
Bodhisattva
Bodhisattva


Joined: 23 Sep 2003
Posts: 7221
Location: Sat in front of my computer

PostPosted: Mon Jan 09, 2012 1:00 pm    Post subject: Reply with quote

Moved from Gentoo Chat to Networking & Security as it's a support question rather than something about Gentoo itself.

I'd agree with BoneKracker, the best thing to do with a rooted box is wipe it and start again.
_________________
Search | Read | Answer | Report | Strip
Back to top
View user's profile Send private message
phajdan.jr
Retired Dev
Retired Dev


Joined: 23 Mar 2006
Posts: 1777
Location: Poland

PostPosted: Mon Jan 09, 2012 4:10 pm    Post subject: Reply with quote

Yup, don't try to be smart, you can never be sure if you've removed everything. Once it's rooted, game over.

Just make sure it's really the router, and ideally capture a forensic image of the HDD (unfortunately your re-emerged could have overwritten something interesting or triggered some covering of tracks).

It's also a good idea to change all passwords and keys in the network for obvious reasons.
_________________
http://phajdan-jr.blogspot.com/
Back to top
View user's profile Send private message
WxY
n00b
n00b


Joined: 25 Apr 2011
Posts: 16

PostPosted: Tue Jan 10, 2012 3:46 am    Post subject: Reply with quote

ugh, is it really a complete necessity to reimage? I have a software raid + LVM rootfs config that is really hard to migrate. Though I've partitioned system and data separately.. Could I get away with just nuking system partitions?
Back to top
View user's profile Send private message
Hu
Administrator
Administrator


Joined: 06 Mar 2007
Posts: 23100

PostPosted: Tue Jan 10, 2012 4:50 am    Post subject: Reply with quote

You can preserve some content if you are willing to risk preserving the infection. In my opinion, no matter how much trouble it is to recreate the existing layout, you will be better off wiping and reinstalling from scratch.
Back to top
View user's profile Send private message
WxY
n00b
n00b


Joined: 25 Apr 2011
Posts: 16

PostPosted: Thu Jan 12, 2012 8:25 am    Post subject: Reply with quote

Ok I packed and scanned most of my data files, nuked the disks with full drive dd's.

i just Audited my configs. Turns out one of the users in wheel had a weak password ND had SSH rights. That prolly did the trick.

MOst of my local services are restored and the box can talk to the net again. This time i aint letting will do daily penetration testing against passwds for all remote capable users...

Though a new problem came up. for some reason it won't forward packets anymore o_O. So I had to post this on my phone. Thus the awful typing. Any recommendations?

Edit: Nevermind. I forgot about the classic MTU problem. Building a tcpmss capable kernel now :]
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum