?hack cause?

From: Andy Gabor (ajgabor@ucdavis.edu)
Date: 03/25/02


From: Andy Gabor <ajgabor@ucdavis.edu>
Date: Mon, 25 Mar 2002 11:30:08 -0800
To: <focus-sun@securityfocus.com>


Hi, I think I got hacked but not sure how.

Env: Sol8 (all security patches installed - I think), Ultra 10

Log:
Mar 23 08:12:39 nova inetd[160]: [ID 858011 daemon.warning] /usr/dt/bin/rpc.cmsd: Killed
Mar 23 08:12:44 nova inetd[160]: [ID 858011 daemon.warning] /usr/dt/bin/rpc.ttdbserverd: Killed
Mar 23 08:12:56 nova inetd[16315]: [ID 161378 daemon.error] ftp/tcp: bind: Address already in use
Mar 23 08:12:56 nova inetd[16315]: [ID 161378 daemon.error] telnet/tcp: bind: Address already in use
Mar 23 08:12:56 nova inetd[16315]: [ID 161378 daemon.error] uucp/tcp: bind: Address already in use
Mar 23 08:12:56 nova inetd[16315]: [ID 161378 daemon.error] time/tcp: bind: Address already in use
Mar 23 08:12:56 nova inetd[16315]: [ID 161378 daemon.error] echo/tcp: bind: Address already in use
Mar 23 08:12:56 nova inetd[16315]: [ID 161378 daemon.error] discard/tcp: bind: Address already in use
Mar 23 08:12:56 nova inetd[16315]: [ID 161378 daemon.error] daytime/tcp: bind: Address already in use
Mar 23 08:12:56 nova inetd[16315]: [ID 161378 daemon.error] chargen/tcp: bind: Address already in use
Mar 23 08:12:56 nova inetd[16315]: [ID 161378 daemon.error] fs/tcp: bind: Address already in use
Mar 23 08:12:56 nova inetd[16315]: [ID 161378 daemon.error] printer/tcp: bind: Address already in use
Mar 23 08:12:56 nova inetd[16315]: [ID 161378 daemon.error] dtspc/tcp: bind: Address already in use
Mar 23 08:12:56 nova inetd[16315]: [ID 161378 daemon.error] pop3/tcp: bind: Address already in use

Effect:
1. lost /usr/dt/bin/rpc.cmsd
2. new files /usr/bin/login /usr/bin/.login.

Checked sunsolve for cmsd alerts - none.

Any insights appreciated.

Andy

=====================================================================
Andy Gabor - Department of Neurology, University of California, Davis
ajgabor@ucdavis.edu (530)754-5036 (FAX)



Relevant Pages

  • Re: Munich review
    ... Many have lost siblings, ... >>It's not that simple, Andy. ... >>death as an ideal given by their God. ... > feel about the imposition of Noachide laws upon their culture. ...
    (soc.culture.jewish.moderated)
  • Re: Error Accessing File - Need Nurse maid
    ... Andy this sounds like this very nasty old corruption: ... Network connection may have been lost." ... Andy Pagorek ...
    (microsoft.public.access.reports)
  • Re: Yes
    ... Lou, ... I agree with most of your statement, but I think Andy has lost Brain cells ... I blame Reid more than anyone for this season. ...
    (alt.sports.football.pro.phila-eagles)
  • Re: Last Chance - HUGE Commodore Lot - Pickup Only - eBay Listing
    ... Andy ... >> Too bad you won't ship any of it. ... > Hopefully this stuff gets picked up by someone so it doesn't get lost to ...
    (comp.sys.cbm)
  • Re: NHS dentists
    ... > I used to try to get lost deliberately, ... Did yuh see the sign, ... (Andy called me Edith so i've decided to be called Edith. ...
    (uk.local.cumbria)