LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Debian
User Name
Password
Debian This forum is for the discussion of Debian Linux.

Notices


Closed Thread
  Search this Thread
Old 10-13-2011, 01:51 PM   #1
rewesh
LQ Newbie
 
Registered: Oct 2011
Posts: 12

Rep: Reputation: Disabled
Red face Server is infected with rootkit or something


My system is infected with a rootkit or something and i trying to find the source of the infection but i can not. I though by doing an upgrade from etch to lenny will help, however the process is halted by an error to upgrade Mysql which i do not want to update for he moment. I found this bot file attached in the tmp folder. i had to put .txt so i can attach it
Attached Files
File Type: txt bot.txt (17.4 KB, 34 views)
 
Old 10-13-2011, 02:10 PM   #2
craigevil
Senior Member
 
Registered: Apr 2005
Location: OZ
Distribution: Debian Sid/RPIOS
Posts: 4,883
Blog Entries: 28

Rep: Reputation: 533Reputation: 533Reputation: 533Reputation: 533Reputation: 533Reputation: 533
Did you run rkhunter and/or chkrootkit?

If there is a rootkit upgrading isn't going to get rid of it.

If you are still running Etch not really surprising that it has a rootkit since support for it stopped in Feb.
 
Old 10-13-2011, 02:12 PM   #3
rewesh
LQ Newbie
 
Registered: Oct 2011
Posts: 12

Original Poster
Rep: Reputation: Disabled
yes i run both of them and they detect nothing, i am running mix system now etch+lenny
 
Old 10-13-2011, 02:14 PM   #4
Hungry ghost
Senior Member
 
Registered: Dec 2004
Posts: 1,222

Rep: Reputation: 667Reputation: 667Reputation: 667Reputation: 667Reputation: 667Reputation: 667
Since it's a security issue, I would suggest you to report your own post and ask a moderator to move it to the Security section of the forum (you'll probably find more help about this specific problem there). After you've got help from the folks at the security section, you will probably want to install something newer, like Debian Squeeze (with new passwords, of course). Debian lenny is still too old, and this could pose a security risk.

Regards.
 
Old 10-13-2011, 03:27 PM   #5
Dutch Master
Senior Member
 
Registered: Dec 2005
Posts: 1,686

Rep: Reputation: 124Reputation: 124
First thing you do is pull the plug. Not shutdown or power down, just pull the plug! Remove the harddrive(s) then use a separate machine (no network connectivity!) and a live-cd to create a copy of the disk. Work on the copy to find a cure, once you found it you can cleanse out the original disk(s). Make sure any data you rescue from the infected drive(s) is thoroughly checked by the updated rootkit scanner available from the rescue cd.

Anyway, your security system is compromised, so you'd really need to rethink your strategy on that and find the source of the infection to make sure it'll never happen again. The most common cause is ignorant users or compromised updates. As said, Lenny is quite old so you really must upgrade to Squeeze now.

I also concur to have the post moved to the Security area of LQ, with much better experts then I'll ever be
 
Old 10-14-2011, 04:57 AM   #6
ring0
LQ Newbie
 
Registered: Jul 2011
Distribution: Debian
Posts: 10

Rep: Reputation: Disabled
I scanned the file with avast online scanner http://onlinescan.avast.com/ and reports it as Perl:Shellbot-T [Trj].After googling i found this http://www.anchiva.com/virus/view.as...erl.Shellbot.a, it is an irc bot.

Last edited by ring0; 10-14-2011 at 04:59 AM.
 
Old 10-14-2011, 06:17 AM   #7
TobiSGD
Moderator
 
Registered: Dec 2009
Location: Germany
Distribution: Whatever fits the task best
Posts: 17,148
Blog Entries: 2

Rep: Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886
Duplicate of http://www.linuxquestions.org/questi...ething-908008/
 
Old 10-14-2011, 10:32 AM   #8
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
This thread is being closed because it is a duplicate. Please continue here: http://www.linuxquestions.org/questi...ething-908008/.
 
  


Closed Thread



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Server infected with scanssh, pscan2, ./sshf. zaeem Linux - Security 4 08-05-2010 06:45 PM
rootkit hunter false positive for Xzibit Rootkit on CentOS 4.8? abefroman Linux - Security 2 12-20-2009 08:19 AM
server (Redhat) compromised by Suckit Rootkit! Thanks for help! a_whitecloud Linux - Security 5 07-14-2006 08:49 AM
locate infected machine from dhcp server erimar77 Linux - General 2 05-20-2006 09:33 AM
rootkit: infected??? help synaptical Linux - Security 4 05-16-2005 07:11 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Debian

All times are GMT -5. The time now is 06:27 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration