Re: New t0rnkit v9 / Bobkit rootkit or maybe worm attack

From: Cichlidiot (fishlover@nospam.net)
Date: 01/19/02


From: Cichlidiot <fishlover@nospam.net>
Date: Sat, 19 Jan 2002 02:17:12 +0000 (UTC)

Angelo Mandato <amandato@mcs.kent.edu> wrote:
> I have found the same hack/worm within my machine. Does anyone know
> the extent of the attack? My machine did not have anything
> substantial but it was acting as a firewall for my personal machine.
> That has become my concern.

Did you have services running on a firewall box? A firewall box should not
be running services. So far, evidence is that the attack comes through
wu_ftpd or sshd. Your best option is to reinstall the machine. Save an
image of the drive if you are interested in saving evidence of the attack
(using the dd command for example). This time reinstall the machine with
its goal as purely a firewall in mind. If you're using a *nix distro that
is not aimed for being a minimalistic firewall, then use the expert setup
for your distro of choice (if available) and minimalize what is installed.
No services, no X-Windows, etc. If there are vendor patches for anything
you have installed, apply the patches. Your goal is just a basic system
and the firewall. If you absolutely can't put a console login solution on
the box, then make sure to firewall the access to sshd such that ONLY your
internal interface is allowed access.



Relevant Pages

  • RE: [Full-Disclosure] Sidewinder G2
    ... Secure Computing Sidewinder G2 Firewall Stops New High-Profile Sendmail ... Technology Prevents Sendmail Attack Warned About in CERT Advisory ...
    (Full-Disclosure)
  • RE: Thinking about Security rules...
    ... > Subject: Re: Thinking about Security rules... ... >>rules for the IDS. ... by which you attack. ... firewalls in series isn't nearly as nice as a stateful firewall coupled ...
    (Vuln-Dev)
  • Re: Can I protect myself against network attacks?
    ... > I guess that was one purpose of the attack. ... > had happened if you just used the SP2 firewall which does not warn you ... back, I've seen the firewall crash before my eyes, without warning. ... network attacks, or trojans. ...
    (comp.security.firewalls)
  • Re: Firewall security: Re: Problems with simple Samba file share
    ... >>million doesn't change my action of deploying a firewall ONCE. ... They keys can be obtained ... > What I suspect is that you think a special attack will be developed ... the firewall helps protect us. ...
    (comp.os.linux.misc)
  • Re: I was hacked
    ... Only me noticing that the requests seemed to come from a LAN? ... To secure IIS somewhat, remove all the virtual directories even if they are ... > Do you have some kind of application level firewall on this machine? ... a series of attempts to attack IIS that the IIS log claimed were coming ...
    (microsoft.public.inetserver.iis.security)