LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 08-17-2005, 09:38 PM   #1
Odins_Son
LQ Newbie
 
Registered: Nov 2004
Location: Salem
Distribution: debian unstable
Posts: 18

Rep: Reputation: 0
Rooted


I did a ps aux and I saw these 3 process and I have no ideo what they are. I haven't seen these before and I was wondering if these are something typical or if I should look into them further. If they aren't something thats usually associated with apache how do I get about getting more info on them. Any suggestions would be appreciated.

apache 16781 0.0 0.0 1572 492 ? S 19:30 0:00 ./jam5
apache 17516 0.0 0.0 1572 492 ? S 20:10 0:00 ./jam5
apache 17665 0.0 0.0 8704 36 ? S 20:18 0:00 ./w00t

Last edited by Odins_Son; 08-18-2005 at 11:14 AM.
 
Old 08-17-2005, 10:12 PM   #2
ilikejam
Senior Member
 
Registered: Aug 2003
Location: Glasgow
Distribution: Fedora / Solaris
Posts: 3,109

Rep: Reputation: 97
Looks like you've been cracked.

Probably something derived from this:
http://www.glug-howrah.org/modules.p...ew&t=6&start=0

Get the machine off-line ASAP.

Dave
 
Old 08-18-2005, 11:14 AM   #3
Odins_Son
LQ Newbie
 
Registered: Nov 2004
Location: Salem
Distribution: debian unstable
Posts: 18

Original Poster
Rep: Reputation: 0
Yeap I've been rooted. I dont think the hacker managed to get root access because all the processes were running as apache. Also my sshd and ftp appear to be wonky now. They allow everyone to log in even though I only have a few users.

I checked my log files and it looks like someone has been picking away at it for some time. the sshd log files are full of failed attempts. I ran chrootkit and rkhunter and they didn't come up with much at all.

I have the server offline and I was hoping to salvage it if possible. Anyone know of any good howtos on doing an extensive cleanup? I'm probably going to end up doing a re-install but I kinda wanted to learn howto undo this and how the rootkit works.

I managed to find the rootkit in /var/tmp. The person actually named it rootkit.
 
Old 08-18-2005, 11:38 AM   #4
ilikejam
Senior Member
 
Registered: Aug 2003
Location: Glasgow
Distribution: Fedora / Solaris
Posts: 3,109

Rep: Reputation: 97
If your attacker managed to alter your FTP and SSH configs, then I'd say it's a fair bet that she does have root on your machine. That being the case any cleanup short of a clean install is asking for trouble. Have a look at root's .bash_history and any other shell histories you can think of. Have a look at /var/log/messages - I don't know about Debian, but RH logs any 'su' events there, through PAM.

As for how the exploit works, I'd open a new thread to see if anyone can answer that. I know the theory behind general cracking methods, but I'm not familiar with any implementations.

Dave

Last edited by ilikejam; 08-18-2005 at 11:41 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Limiting child processes in Apache? Phaethar Linux - Software 2 11-02-2004 05:24 PM
Apache being wierd tethysgods Linux - Software 2 07-03-2004 10:42 AM
Wierd Apache Log Entry cmfarley19 Linux - Software 3 04-23-2004 05:22 AM
so many apache processes cjpsparks Linux - Software 4 01-07-2004 04:54 PM
Runaway apache processes Gardener Linux - Networking 3 01-25-2003 06:56 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 11:43 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration