Re: Urgent!!! My computer seems to be hacked, pls HELP!!!




Todd H. wrote:
"Jenny" <ahajenny@xxxxxxxxx> writes:
Dear groups,

My computer was told that it sent unusual packets from port 60609 to
some computer with IP 61.50.138.237 port 22. (more than 20 flows per
second!!!)

I am running Fedora Core 5 plus "OpenSSH_4.3p2, OpenSSL 0.9.8a 11 Oct
2005", I use netstat to check services I open, only mysql, samba,
vsftp, ssh, http.

I check /var/log, message and security. I can't find any successful
logging from others. But I do find many many attacks from 61.50.138.*
(not including the one 61.50.138.237 which my computer attacked!!!),
and none of them successes.

I have some questions to ask all of you, please help me!!!

1. is my computer hacked? if no, then why my computer sends packets
from port 60609 to some computer port 22 ?

If neither you nor any authorized user to your knowledge is using the
machine then this ssh connection to an IP in china is very likely a
compromise.


do you mean that my computer is hacked???
well, is it possible that the computer is not hacked, but itself sends
packets to some other computer automatically?

sorry, i think i am asking stupid question, but this really confuses
me!


2. if my computer is hacked, then what can I do? reinstalling the
system is the only way???

Yup. It's the only way to get back to a known state. Wiping and
reinstalling from original media.

--
Todd H.
http://www.toddh.net/

.



Relevant Pages

  • Re: What is going on with my Dialup?
    ... also forward it to an unused port, and have that port provide the ... verses the RST or ICMP 3,3. ... The lack of response causes the remote computer to make ... Others think that by not responding to unwanted packets, ...
    (comp.os.linux.networking)
  • Re: Logs: Many hits with source port of 80
    ... The hits from source port 80 to dest port 37852 are IMHO almost ... you should probably see a couple other packets - perhaps ... packets if either you send the load balancer a packet, ... >>I have seen similar hits for the past three months. ...
    (Incidents)
  • Re: Error 720 connecting to server via VPN
    ... By default the router's firewall is configured to drop ICMP packets ... Select WAN Setup> Advanced> Respond to Ping on Internet Port. ... server and the Internet allow GRE packets. ... routers on the user's network are also configured to allow GRE packets. ...
    (microsoft.public.windows.server.sbs)
  • tcp oddities.
    ... After syn-scanning an IP block, ... suprise there was an smtp server sitting on port 25. ... 1353 packets received by filter ... Ethical Hacking at the InfoSec Institute. ...
    (Pen-Test)
  • Re: What is going on with my Dialup?
    ... also forward it to an unused port, and have that port provide the ... There is a huge debate of whether it's better to provide no response ... The lack of response causes the remote computer to make ... Others think that by not responding to unwanted packets, ...
    (comp.os.linux.networking)