Security Incidents mailing list archives

Re: RH6.1/IPChains box hacked


From: rsavage () CROSSWINDS NET (Rory Savage)
Date: Mon, 24 Apr 2000 19:40:38 -0400


Hide his/her tracks.... how many females are crackers these days?
Most of them are males... age 19 and younger...

Rory Savage

--
Systems Administrator
 email: rsavage () crosswinds net
.-.-.-..---..-..-..---.
| | | || | || .` || |'_
`-----'`-^-'`-'`-'`-'-/
 WANG/MCI/FAA
 work (919)-377-7702
 beep (800)-PAGE-MCI
 page mail: 1433539 () pagemci com

On Mon, 24 Apr 2000, Mark Tinberg wrote:

It looks like a copy of your RPM database.  Possibly the cracker edited and rebuilt your RPM database to hide his/her 
tracks.  Try running a 'rpm --verify --all' and comparing the output to 'rpm --verify 
/path/to/cdrom/RPMS/packagename.rpm' or 'rpm --verify ftp://ftp.redhat.com/path/to/RPMS/pachagename.rpm' (using a 
known, trusted copy of the RPM executable of course.)  This will compare checksumms from the RPM database and then 
from the actual package files you have installed, they should match (you should be able to trust that your CDROM or 
ftp.redhat.com is OK.)  If not then not only are your executables trojaned/backdoored/etc. but your RPM database is 
suspect as well.  Probably a good idea to always verify off trusted media as opposed to trusting the RPM database 
hasn't been altered.


"J. J. Horner" <jhorner () KNOXLUG ORG> 04/21/00 16:22 PM >>>
FYI:

I was hacked last week throught Bind 8.2.2_P3.  If anyone can look at my
logs and tell me some thoughts it would be good.  The intruder erased all
of the logs (/var/log/mesages*) on my box, but didn't notice or didn't
check to see that all logging was duplicated to another machine (*.*
@JJ1) in /etc/syslog.conf.




Current thread: