LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-19-2010, 03:54 PM   #16
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600

Quote:
Originally Posted by proNick View Post
Ok, tnx, there was some intruder, but it will be ok.
No it will not be OK. Your machine running an "online shop application written in php" clearly was not investigated well enough to help prevent the second wave of attacks. Blithely continuing on your current course, ignoring facts and opening new threads as if nothing happened, is not the way to ensure data safety and costumer trust.
- If you fixed things then please tell us what the infection vector was and what you did to ensure this does not happen again.
- If you think you could use our freely available help then all you have to do is cooperate and post the information requested.
- If you want to look for help elsewhere I suggest hiring a capable admin.
 
Old 06-19-2010, 05:07 PM   #17
salasi
Senior Member
 
Registered: Jul 2007
Location: Directly above centre of the earth, UK
Distribution: SuSE, plus some hopping
Posts: 4,070

Rep: Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897
Quote:
Originally Posted by proNick View Post
hello,

now after few months, i have same problem.

all i have is report from provider:

Log entries related to these addresses (times are in CEST (UTC +02:00)):
Start End Sif SrcIPaddress SrcP DIf DstIPaddress DstP P Fl Pkts Octets
0613.12:26:23.983 0613.12:27:45.143 145 xxx.yy.zz.q 32906 269 ppp.qqq.rr.1 22 17 0 158233 6804019
0613.12:27:45.145 0613.12:28:49.501 145 xxx.yy.zz.q 32906 269 ppp.qqq.rr.1 22 17 0 39449 1696307
0613.12:32:09.947 0613.12:32:14.669 145 xxx.yy.zz.q 32908 553 ppp.qqq.rr.2 22 17 0 8861 381023
0613.12:43:14.871 0613.12:44:47.420 145 xxx.yy.zz.q 32912 269 ppp.qqq.rr.6 22 17 0 8334005 358362215
0613.12:44:47.422 0613.12:46:23.390 145 xxx.yy.zz.q 32912 269 ppp.qqq.rr.6 22 17 0 8739423 375795189
0613.12:46:23.390 0613.12:47:18.481 145 xxx.yy.zz.q 32912 269 ppp.qqq.rr.6 22 17 0 4951330 212907190
by 'the provider' you mean the organisation that provides hosting to you...

If this is the case, be aware that things have now become worse:
  • Previously, there was evidence and a likelihood that your system was causing the problem, now there is something that could be described as proof.
  • There was a problem; you have tried to deal with it, without causing disruption. That didn't work.
  • Having had the problem twice, there can be a limited amount of tolerance for ineffectual 'cures' from here on in.

If nothing else, I would like to know from my own point of view, what was the true cause, so that I know as much as possible which attack vectors are currently 'live'.

Quote:
what will be your advice, what to do?
for pity's sake:
  • take it very seriously
  • try to find the problem and cure that problem
  • continue to take security seriously, please: if this continues, if your provider doesn't cut you off, the credit card orgs probably will, unless you can demonstrate compliance and if you tried to do that in your current situation, they'd have your head on a spike so fast it wouldn't even hurt
 
Old 06-21-2010, 04:08 PM   #18
salasi
Senior Member
 
Registered: Jul 2007
Location: Directly above centre of the earth, UK
Distribution: SuSE, plus some hopping
Posts: 4,070

Rep: Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897
Apologies to everyone else who is subscribed to this thread, but could I make an additional plea to the Original Poster to start answering the questions asked, in particular the questions asked in the original post by unSpawn, who asked some very specific questions, the answers to which would help in pinpointing the specific problem.

I must repeat unSpawn's case (and Hangdog42 and GrapefruiTgirl) that there is no point just now in generic, good practice, advice, nice as that may be in the slightly longer term, when there is a specific problem that needs to be attacked urgently.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Abuse report brgsousa Linux - Security 1 12-16-2008 02:08 PM
LXer: OOXML Abuse Index: Please Register Your Complaint by 29/5/08 LXer Syndicated Linux News 0 05-26-2008 11:10 AM
Abuse prashantbhushan Linux - Networking 1 11-23-2006 05:34 AM
email abuse ice99 General 3 11-20-2005 09:55 AM
Email abuse Jon Doe Linux - Security 25 07-01-2005 03:59 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:06 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration