HELP - Have attack my Server

This is a discussion on HELP - Have attack my Server within the Linux Security forums, part of the System Security and Security Related category; Hi, I have a server with Qmail, Apache2, Freeradius, MySQL and BIND. I have firewalled this server with open port ...


Go Back   Usenet Forums > System Security and Security Related > Linux Security

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 08-13-2004
Pisinho
 
Posts: n/a
Default HELP - Have attack my Server

Hi,
I have a server with Qmail, Apache2, Freeradius, MySQL and BIND.

I have firewalled this server with open port of this service.

Recently I have found this daemon which running :

../https www.uol.com.br 80 10000 xx

My bandwith is down, and don't have idea where is the bug,
I have change the password for root and unique user but the attacker is
every logged...

Please help me.

P.S.: don't have log, the hacker clean the log....


Thanks.


--
Posted via Mailgate.ORG Server - http://www.Mailgate.ORG
Reply With Quote
  #2 (permalink)  
Old 08-13-2004
Tim Haynes
 
Posts: n/a
Default Re: HELP - Have attack my Server

"Pisinho" <linux@fol.it> writes:

> I have a server with Qmail, Apache2, Freeradius, MySQL and BIND.
>
> I have firewalled this server with open port of this service.
>
> Recently I have found this daemon which running :
>
> ./https www.uol.com.br 80 10000 xx
>
> My bandwith is down, and don't have idea where is the bug,
> I have change the password for root and unique user but the attacker is
> every logged...


So now they know
a) you're onto them
b) root's new password
c) what users are important to you
d) what their password-choice strategy is like.

That was not clever.

> Please help me.
>
> P.S.: don't have log, the hacker clean the log....


<http://www.cert.org/tech_tips/win-UNIX-system_compromise.html>

<http://www.linuxsecurity.com/docs/colsfaq.html> as well. What didn't you
do right, in order to get cracked?

~Tim
--
13:30:37 up 16 days, 18:21, 3 users, load average: 0.01, 0.11, 0.15
piglet@stirfried.vegetable.org.uk |As long as I can see the morning
http://spodzone.org.uk/cesspit/ |And blossom turns to bud again in spring
Reply With Quote
  #3 (permalink)  
Old 08-13-2004
Gandalf Parker
 
Posts: n/a
Default Re: HELP - Have attack my Server

"Pisinho" <linux@fol.it> wrote in
news:b3f87c4181d697d1fd51fd431d9fb405.100471@mygat e.mailgate.org:

> P.S.: don't have log, the hacker clean the log....


You didnt say what linux you have.
Sounds like it might be an older rootkit.
Try these commands...

ls -blaRt /dev |grep "^-"
grep -v :x: /etc/passwd
find / |grep tcp.log

You might also try..
strings /bin/ps |grep /
but that is going to give you some results. Unless you have seen it before
you might not spot the change

Gandalf Parker
Reply With Quote
  #4 (permalink)  
Old 08-15-2004
jayjwa
 
Posts: n/a
Default Re: HELP - Have attack my Server

On 2004-08-13, Pisinho <linux@fol.it> wrote:
> Hi,
> I have a server with Qmail, Apache2, Freeradius, MySQL and BIND.
>
> I have firewalled this server with open port of this service.
>
> Recently I have found this daemon which running :
>
> ./https www.uol.com.br 80 10000 xx
>
> My bandwith is down, and don't have idea where is the bug,
> I have change the password for root and unique user but the attacker is
> every logged...
>
> Please help me.
>
> P.S.: don't have log, the hacker clean the log....



I see the "test"/"guest" SSH attacks got you :P


--
--- SIGSEGV (Segmentation fault) @ 0 (0) ---
+++ killed by SIGSEGV +++
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 12:31 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0