RE: Have I been kitted?

From: Tim Howes (thowes@ssi-ltd.com)
Date: 06/13/02


From: "Tim Howes" <thowes@ssi-ltd.com>
To: <focus-linux@securityfocus.com>
Date: Thu, 13 Jun 2002 10:00:06 +0100

Terry

I have had this before, you could have a corrupt ps binary so therefore not
able to see the process when doing a ps -aux command, try and get a new ps
binary on that machine then run one and then you're corrupt one, if you then
compare the outputs you will see the hidden process. Other processes to
check for corruption would be du, ls, df, lsof and find.

You should be able to clean the machine if it is critical for a network, but
if you are in a position where formatting and starting again is not a
problem then do that. However you should take steps to work out how you
were compromised and then take steps to secure for the future. Are you
running portsentry or other programs to prevent attack. Have you got old
insecure versions of openssh running etc.

When I saw this on my machine I later found out that I had bobkit installed,
luckily I had a local machine here that once not on the network and so could
just pull off the clean binaries.

http://www.stearns.org/detectlib/bobkit.html for a description of the kit
itself.

Good news is that I have recently received an email saying that the hacking
crew that did this to me as been caught!

Regards

Tim Howes



Relevant Pages

  • Re: corrupt body tag
    ... Your example has extra tags. ... occurring to cause FrontPage code to corrupt in this manner ... A new network was installed recently in the office where this website is being administered then the local hard drive crashed and a new one installed. ... The network administrator replaced the programs and load FrontPage to "help" ...
    (microsoft.public.frontpage.programming)
  • Re: Indirect Rep & Search Key Not Found Error
    ... the network would drop out for certain ... and an interruption to that would likely corrupt the ... replica farms on every PC for your sanity sake. ... We've got the latest Jet, MDAC, Office 2003 ...
    (microsoft.public.access.replication)
  • Re: Excel crash when using user defined chart
    ... are having difficulty with is stored in some shared location on the network? ... I think you can try a utility called Advanced Excel Repair. ... rather well for my corrupt Excel xls files. ...
    (microsoft.public.excel)
  • Re: Error installation SQL Server 2005
    ... You could verifiy the message setup is giving you. ... Copy the file sql.cab from CD (or network) to your local c:\ drive. ... file is corrupt. ... > I am trying to install SQL Server 2005 on windows 2003 server standard ...
    (microsoft.public.sqlserver.setup)
  • Re: Table is corrupt
    ... Altman wrote: ... > I have a customer who gets an error saying that a table "has become ... Tables can become corrupt if the computer is disconnected from the network ...
    (microsoft.public.fox.programmer.exchange)