Security Incidents mailing list archives
Re: RH6.1/IPChains box hacked
From: rsavage () CROSSWINDS NET (Rory Savage)
Date: Mon, 24 Apr 2000 19:40:38 -0400
Hide his/her tracks.... how many females are crackers these days? Most of them are males... age 19 and younger... Rory Savage -- Systems Administrator email: rsavage () crosswinds net .-.-.-..---..-..-..---. | | | || | || .` || |'_ `-----'`-^-'`-'`-'`-'-/ WANG/MCI/FAA work (919)-377-7702 beep (800)-PAGE-MCI page mail: 1433539 () pagemci com On Mon, 24 Apr 2000, Mark Tinberg wrote:
It looks like a copy of your RPM database. Possibly the cracker edited and rebuilt your RPM database to hide his/her tracks. Try running a 'rpm --verify --all' and comparing the output to 'rpm --verify /path/to/cdrom/RPMS/packagename.rpm' or 'rpm --verify ftp://ftp.redhat.com/path/to/RPMS/pachagename.rpm' (using a known, trusted copy of the RPM executable of course.) This will compare checksumms from the RPM database and then from the actual package files you have installed, they should match (you should be able to trust that your CDROM or ftp.redhat.com is OK.) If not then not only are your executables trojaned/backdoored/etc. but your RPM database is suspect as well. Probably a good idea to always verify off trusted media as opposed to trusting the RPM database hasn't been altered."J. J. Horner" <jhorner () KNOXLUG ORG> 04/21/00 16:22 PM >>>FYI: I was hacked last week throught Bind 8.2.2_P3. If anyone can look at my logs and tell me some thoughts it would be good. The intruder erased all of the logs (/var/log/mesages*) on my box, but didn't notice or didn't check to see that all logging was duplicated to another machine (*.* @JJ1) in /etc/syslog.conf.
Current thread:
- Re: RH6.1/IPChains box hacked Mark Tinberg (Apr 24)
- Re: RH6.1/IPChains box hacked Rory Savage (Apr 24)
- Weird traceroutes Donald McLachlan (Apr 26)
- <Possible follow-ups>
- Re: RH6.1/IPChains box hacked J. J. Horner (Apr 24)
