Re: Root can't delete files

From: William York (why317@yahoo.com)
Date: 10/10/01


Message-ID: <20011010190725.35640.qmail@web11601.mail.yahoo.com>
Date: Wed, 10 Oct 2001 12:07:25 -0700 (PDT)
From: William York <why317@yahoo.com>
Subject: Re: Root can't delete files
To: Thanas <thanas@infinito.it>, Focus Linux <focus-linux@securityfocus.com>


>
> after an intrusion in a linux system (2.2) using (I suppose) a
> vulnerability in bind 8.2.2 I've experienced a strange behaviour:
>

I'd say it's time to upgrade to a later version of BIND.

>
> the attacker installed a corrupted version of /bin/login
>

If /bin/login is suspect, what makes you think the rest of the system
is O.K.?

> and when i typed:
>
> # mv /safe/version/path/login /bin/login
>
> I just obtained the message 'Operation not permitted' ... How is
> it possible ? I had to use low level tools directly on the ext2
> filesystem to delete that file ...
>

Um, I'd look first at a corrupted version of 'rm', 'mv' and all other
executables. I would personally recommend that you back up critical
data and baseline the system, making sure that you change all
passwords along the way. Once the system has been compromised once,
especially as 'root', it's very hard and very tedious to repair it.

Good luck,
-Bill

__________________________________________________
Do You Yahoo!?
Make a great connection at Yahoo! Personals.
http://personals.yahoo.com



Relevant Pages

  • Re: how to change roots shell
    ... Im going to see if I can walk a user at the site through single user mode. ... su to root or even login as root. ... Do You Yahoo!? ... Mail has the best spam protection around ...
    (freebsd-questions)
  • Debian Woody login problem
    ... wipe it out and install Sarge as my main OS, ... "can't authenticate" warning. ... when I'm logged into the second drive as root ... New and Improved Yahoo! ...
    (Debian-User)
  • Re: How to change home page?
    ... Root: HKEY_CURRENT_USER ... The registry Start Page showed the new address http://my.att.net but when I ... Feel free to remove *any* ATT or Yahoo! ... for cookies, only one folder for Temp files, one folder for IE temp cache, ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: need help as soon as possible
    ... > and tried to connect to yahoo through it but it suddenly frozen and i ... > login screen.i tried logging in as root it worked, ... > new sesion' i tried to open new sesion as the user, nothing happened, ...
    (alt.os.linux.suse)
  • Re: error
    ... There maybe was some sort of ".yahoo" directory. ... To wipe all these settings, it would have been enough to do this command: ... Never mis-use "root" for such stuff!! ... These are leftovers from your previous user account that apparently had ...
    (alt.os.linux.suse)