Re: LKM Trojan installed

From: Brian Hatch (focus-linux@ifokr.org)
Date: 02/08/03

  • Next message: Shawn M. Jones: "Re: LKM Trojan installed"
    Date: Sat, 8 Feb 2003 12:24:34 -0800
    From: Brian Hatch <focus-linux@ifokr.org>
    To: terry white <twhite@aniota.com>
    
    
    

    > ... i created a directory, copied 'ps' et al to it, and used chattr on
    > them. having a known good binary outside $PATH is something of a comfort
    > ...

    Of course, if the cracker has gotten root, they can chattr it right
    back. In fact, the first thing I'd do as an attacker is to find all
    chattr'd files on the filesystem since they're probably important.

    The only way to be absolutely sure you see the real state of the
    filesystem is to boot off of pristine read-only media. When you've
    verified all the binaries and checked for any unusual startup actions
    (/etc/rc?.d, /etc/inittab, initrd device, etc) which could modify things
    then you can trust your ps commands -- as long as the attacker doesn't
    come in and modify things again. (You should work without the network
    plugged in until you're sure things are sane.)

    --
    Brian Hatch                  Dijon vu: the same
       Systems and                mustard as before.
       Security Engineer
    http://www.ifokr.org/bri/
    Every message PGP signed
    
    




    Relevant Pages

    • BSD Securelevels: Circumventing protection of files flagged immutable
      ... By mounting an arbitrary filesystem, it is possible to mask files ... different levels of security. ... With Linux an attacker can even intercept the password input to lower ... Administrators should furthermore not rely on securelevels ...
      (Bugtraq)
    • [Full-disclosure] BSD Securelevels: Circumventing protection of files flagged immutable
      ... By mounting an arbitrary filesystem, it is possible to mask files ... different levels of security. ... With Linux an attacker can even intercept the password input to lower ... Administrators should furthermore not rely on securelevels ...
      (Full-Disclosure)
    • RE: [fw-wiz] Securing a Linux Firewall
      ... Move all of your utilities to file mounted as a filesystem ... > If the binary grants no additional privileges, then it can do nothing the ... > attacker couldn't do already. ...
      (Firewall-Wizards)
    • Re: freebsd-security Digest, Vol 187, Issue 4
      ... I was so transfixed on Josh stating that the attacker could as well ... just mount a filesystem with suid root binaries and how that would be ... more useful than a buffer overflow in the filesystem driver. ... In the past we have considered remote DOS type attacks to be a security ...
      (FreeBSD-Security)
    • Re: SSL info
      ... You're obviously assuming that an attacker ... can get to the unsecured content and modify it. ... attacker accessing files on a secure area as well? ... the communication between the webserver and client, how are the SSL ...
      (alt.computer.security)