Re: Linux workstation got hacked!

From: Luke Vogel (luke@bell-bird.com.au)
Date: 12/11/02


From: Luke Vogel <luke@bell-bird.com.au>
Date: Wed, 11 Dec 2002 18:38:19 +1000

Et cetera wrote:

> My Linux workstation has been hacked.
>
> Running redhat 5.2.
>
> Accidently noticed the /etc/passwd file modified, the last line
> changed to:
>
> r00t:x:0:0::/usr/sbin/r00t:/bin/bash

[snip]

> adore-0.14.tar.gz*

[snip]

> Files are modified or replaced all over the system! In /usr/bin, /bin,
> /etc,
> and elsewhere. Such as /usr/bin/pstree and /usr/bin/gaura and

[snip]

> How can the hacker or his source be identified?

> in/etc/ftpusers) FROM p50888FD6.dip.t-dialin.net [80.136.143.214],
> [1221]: failed login from lns08a-9-230.w.club-internet.fr

[snip]

Judging by the ease with which you discovered the files (including the
"adore" kernel module) I'd say that you are the victim of a SK (script
kiddie) and a reasonable poor one at that.

Those entries in your messages file indicate that your cracker "may"
have come from isp's in Germany and/or France, but there is a chance
that they were using another cracked box to get into yours.

Unless you can prove significant financial loss, there is probably
little to be gained by tracking the kids down. :(

> What's the best version of Redhat to install. Also what firewall
> should I run.

The best version of *any* distro is the version you keep up to date!

Iptables is my firewall of choice.

> This is really terrible. Any thoughts would be greatly appreciated.

No much to do but learn from the experience and make sure you keep your
software up to date and don't be running *any* unnecessary services.

The url in my sig will give you some good pointers.

-- 
Regards
Luke
------
When I die, I want to die like my Grandmother who died peacefully
in her sleep. Not screaming like all the passengers in her car.
------
C.O.L.S FAQ - http://www.linuxsecurity.com/docs/colsfaq.html
------


Relevant Pages

  • Re: SOHO3 And FTP
    ... I'm running RedHat 7.3. ... >> aren't a result of the firewall. ... > hard drive, and two network cards. ... and if it's a web server you're running you can ...
    (comp.security.firewalls)
  • Re: SOHO3 And FTP
    ... Bob wrote: ... I'm running RedHat 7.3. ... > won't let the Adobe GoLive FTP client through at all. ... All of the above works from machines behind the firewall ...
    (comp.security.firewalls)
  • Re: firewall trouble
    ... > I am running Redhat 7.2 using pmfirewall as my firewall (an IPchains ... If you're running sendmail, check http://www.sendmail.org. ...
    (comp.os.linux.security)
  • Re: freeswan on linux connecting to checkpoint VPN-1 and radius server
    ... > i am running redhat 7.1 with IPSEC compiled into my kernel and am ... > using freeswan to try to connect to my company firewall which is running ... > the radius servers ip is 33.3.3.33 as is routed to by the firewall ...
    (comp.security.unix)
  • editing /etc/sysconfig/iptables to fix DNS problem
    ... Running Redhat 9 ... I am running a DNS server and apparently port 53 was being blocked by ... my firewall. ... says this is not the recommended procedure. ...
    (comp.os.linux.security)