LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 01-13-2005, 12:46 PM   #1
drj000
Member
 
Registered: Sep 2004
Location: Houston, TX
Distribution: Fedora
Posts: 261

Rep: Reputation: 33
Did I get hacked?


Something weird has happened on my computer, and I think I may have been hacked.
In my LogWatch, I had this entry
Code:
--------------------- Connections (secure-log) Begin ------------------------ 

New Users:
   useradd (named)

New Groups:
   named (25)
I thought, who added a new user, and why? So I looked in /var/log/secure, and it said
Code:
Jan 12 22:44:49 resnet-18-64 groupadd[6798]: new group: name=named, gid=25
Jan 12 22:44:49 resnet-18-64 useradd[6799]: new user: name=named, uid=25, gid=25, home=/var/named, shell=/sbin/nologin
So, I then checked /var/named. Here's the directory listing.
Code:
total 72
drwxrwx---  2 named named 4096 Oct 18 16:17 data
-rw-r--r--  1 named named  198 Aug 25 17:16 localdomain.zone
-rw-r--r--  1 named named  195 Aug 25 17:16 localhost.zone
-rw-r--r--  1 named named  415 Aug 25 17:16 named.broadcast
-rw-r--r--  1 named named 2518 Aug 25 17:16 named.ca
-rw-r--r--  1 named named  432 Aug 25 17:16 named.ip6.local
-rw-r--r--  1 named named  433 Aug 25 17:16 named.local
-rw-r--r--  1 named named  416 Aug 25 17:16 named.zero
drwxrwx---  2 named named 4096 Oct 18 16:17 slaves
There were no files in the folders data, or slaves. Most of the files had similair contents. Here's named.broadcast:
Code:
$TTL    86400
@               IN SOA  localhost       root (
                                        42              ; serial (d. adams)
                                        3H              ; refresh
                                        15M             ; retry
                                        1W              ; expiry
                                        1D )            ; minimum
	IN	NS	localhost
I really can't make heads or tails of any of this. I was on my computer yesterday at the time this happened, and I was watching TV on my computer, nothing else. So I'm pretty sure nothing I did could have added this new user and group. However, I see that the files in /var/named are several months old. Does anybody have any idea what's going on? Did someone hack into my computer? It doesn't appear like anyone did, but if they did, what would be the purpose?
 
Old 01-13-2005, 02:09 PM   #2
barryman_5000
Member
 
Registered: Jan 2005
Distribution: Gentoo/Vector/Debian
Posts: 95

Rep: Reputation: 15
your ok, I did some googling and found out it was a zoning setup for a firewall. Its nothing and that user was probably added the same time as you installed a firewall. Check if those dates coincide.
 
Old 01-13-2005, 02:41 PM   #3
drj000
Member
 
Registered: Sep 2004
Location: Houston, TX
Distribution: Fedora
Posts: 261

Original Poster
Rep: Reputation: 33
Quote:
Originally posted by barryman_5000
your ok, I did some googling and found out it was a zoning setup for a firewall. Its nothing and that user was probably added the same time as you installed a firewall. Check if those dates coincide.
I've never installed a firewall, of which I'm aware. However, your suggestion helped me figure out what it was. At first, I thought I wasn't doing anything other than watching TV when this happened, but then I realized I ran yum update last night, and it happened to be about the same time. According to yum.log, a few seconds after the user was added, I installed bind, which is a DNS server. I think it was a dependency of something I updated. Anyway, it added that user and group. Thanks for the help. I feel relatively safe again.
 
Old 01-13-2005, 02:54 PM   #4
barryman_5000
Member
 
Registered: Jan 2005
Distribution: Gentoo/Vector/Debian
Posts: 95

Rep: Reputation: 15
Well installing a firewall wouldn't be such a bad idea though
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Have I been hacked? Please help linuxboy69 Linux - Security 11 09-07-2005 07:20 AM
Hacked? mikeshn Linux - Security 2 03-12-2004 01:57 PM
Help! Have I been hacked? Tenover Linux - Security 1 11-19-2003 03:24 PM
Did we just get hacked? vous Linux - Security 4 11-17-2003 08:11 AM
am i being hacked? tearinox Linux - Security 5 11-13-2003 06:00 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 06:38 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration