RE: possible ssh hack

From: Loki (loki@fatelabs.com)
Date: 09/11/02


From: "Loki" <loki@fatelabs.com>
To: "'Ver Allan Sumabat'" <ver_allan@yahoo.com>
Date: Wed, 11 Sep 2002 14:55:05 -0400

What version of SSHD were you running, check commonly exploited
services.

1. SSHD (crc32)
2. FTPD
3. Apache (chunking)

Get back to us with the versions you were running of SSH, FTP, and
Apache and we can help you out. How hardened was the OS? Did you turn
off all RPC services, etc. We need more info.

Eric/Loki
Internet Warfare and Intelligence
Fate Research Labs
www.fatelabs.com

-----Original Message-----
From: Ver Allan Sumabat [mailto:ver_allan@yahoo.com]
Sent: Tuesday, September 10, 2002 6:08 AM
To: incidents@securityfocus.com
Subject: possible ssh hack

Hi,

We have just recently been hacked. I have no idea how
he came in. Here are my preliminary investigations:

1. He was able to add a user without logging in.

**Unmatched Entries**
Sep 5 10:39:33 srv1 sshd[20514]: Could not reverse
map address 10.13.41.4.
Sep 5 10:39:35 srv1 sshd[20514]: Accepted password
for root from 10.13.41.4
port 4207
Sep 5 17:30:36 srv1 sshd[23299]: Could not reverse
map address 10.13.41.4.
Sep 5 17:30:41 srv1 sshd[23299]: Accepted password
for root from 10.13.41.4
port 2491
Sep 5 22:16:59 srv1 useradd[23532]: new group:
name=war, gid=502
Sep 5 22:16:59 srv1 useradd[23532]: new user:
name=war, uid=502, gid=502,
home=/home/war, shell=/bin/bash
Sep 5 22:17:31 srv1 sshd[23534]: Accepted password
for war from
212.179.207.211 port 2746
Sep 5 22:19:17 srv1 sshd[23580]: fatal: Read from
socket failed: Connection
reset by peer
Sep 5 22:21:48 srv1 sshd[928]: Received SIGHUP;
restarting.

2. He installed a tarball w00tkit.tgz in /home/war

3. After running chkrootkit, the significant lines
are:

...
Checking `ifconfig'... INFECTED
...
Searching for Showtee... Warning: Possible Showtee
Rootkit installed
...
Checking `lkm'... You have 1 process hidden for ps
command
Warning: Possible LKM Trojan installed

4. ssh won't run anymore

Can anyone help me on how the intrusion was done?

Thanks.

Regards,

Allan

__________________________________________________
Yahoo! - We Remember
9-11: A tribute to the more than 3,000 lives lost
http://dir.remember.yahoo.com/tribute

------------------------------------------------------------------------

----
This list is provided by the SecurityFocus ARIS analyzer service. For
more information on this free incident handling, management 
and tracking system please see: http://aris.securityfocus.com

---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: Odd ssh attacks?
    ... Here is how I defend against ssh attacks. ... That will stop all traffic to servers like sshd that pay attention to ... Have sshd ALSO listen on a non-standard port and open up your router ...
    (Ubuntu)
  • Re: Latest SSH?
    ... >>scan to check that ssh was the only port visible to the outside world. ... >as that's the last OpenSSH advisory published. ... can sshd be prevented from reporting its version number on ...
    (freebsd-questions)
  • Re: OpenSSH 3.4 and firewalls
    ... sshd process on my machine never acknowledges the request. ... You can see that the ssh client is attempting to connect on the ... correct port, which the firewalls should forward to my machine. ... To verify that the firewall was not at fault, I ran tcpdump with the ...
    (comp.security.ssh)
  • Re: ssh alternatives
    ... I wonder if its possible to run sshd on two different ports on ... separate interfaces.. ... > We run ssh on a non-standard port and have no issues with scripts.... ...
    (RedHat)
  • Re: OpenBSD2.9 ssh to OpenBSD3.0 sshd - Secure connection to <ipaddress> refused.
    ... indicating that nothing is listening on port 22. ... I think ssh is communicating but sending information that sshd ... There is no firewall or packet filter...the machines are connected to the ...
    (comp.security.ssh)