LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-15-2004, 11:47 AM   #1
Lechium
Member
 
Registered: Jun 2004
Distribution: Gentoo
Posts: 102

Rep: Reputation: 16
Computer has restared out of nowehere!


Hi.. I woke up this morning only to find out that my linuxbox (Debian) has restarted all by itself whyile I was sleeping... do you guys have any ideas of how and why thsi could happen?
Sasser worm does similar things to windows boxes, but i though it doesnt exist here...

Last edited by Lechium; 06-15-2004 at 11:56 AM.
 
Old 06-15-2004, 12:06 PM   #2
Deagle
LQ Newbie
 
Registered: Jun 2004
Distribution: ?!
Posts: 23

Rep: Reputation: 15
only thing i can say is that a restart by cpu on its own is similar to sasser worm
and a couple of other worms, they ar low intelligence but not powerfull enough to actually boot your system only to shut it down
i dont know if its possible with OS linux u sure someone in the house didnt start it up
sorry i couldnt be of much help

Regards Deagle
 
Old 06-15-2004, 12:08 PM   #3
Lechium
Member
 
Registered: Jun 2004
Distribution: Gentoo
Posts: 102

Original Poster
Rep: Reputation: 16
Nah the door to my room was locked up.
Maybe power outage, but my windows box is running just fine... wierd... (that is when wondowsbox outperformes linuxbox like that lol)
 
Old 06-15-2004, 12:10 PM   #4
akudewan
Member
 
Registered: Apr 2004
Location: India
Distribution: Ubuntu
Posts: 364

Rep: Reputation: 31
An electricity fluctuation probably?
 
Old 06-15-2004, 01:49 PM   #5
XavierP
Moderator
 
Registered: Nov 2002
Location: Kent, England
Distribution: Debian Testing
Posts: 19,192
Blog Entries: 4

Rep: Reputation: 475Reputation: 475Reputation: 475Reputation: 475Reputation: 475
What do your log files say has happened?
 
Old 06-15-2004, 03:16 PM   #6
Lechium
Member
 
Registered: Jun 2004
Distribution: Gentoo
Posts: 102

Original Poster
Rep: Reputation: 16
How do I access them? =)
 
Old 06-15-2004, 03:24 PM   #7
XavierP
Moderator
 
Registered: Nov 2002
Location: Kent, England
Distribution: Debian Testing
Posts: 19,192
Blog Entries: 4

Rep: Reputation: 475Reputation: 475Reputation: 475Reputation: 475Reputation: 475
In a console type in dmesg. Also look in /var/log and /var/messages (maybe /var/message).

Do you think you have been hacked?
 
Old 06-15-2004, 03:33 PM   #8
scuzzman
Senior Member
 
Registered: May 2004
Location: Hilliard, Ohio, USA
Distribution: Slackware, Kubuntu
Posts: 1,851

Rep: Reputation: 47
It's possible... but wouldn't the computer need to be on for her to have been 'hacked' wouldn't it?
 
Old 06-15-2004, 03:35 PM   #9
XavierP
Moderator
 
Registered: Nov 2002
Location: Kent, England
Distribution: Debian Testing
Posts: 19,192
Blog Entries: 4

Rep: Reputation: 475Reputation: 475Reputation: 475Reputation: 475Reputation: 475
But the computer restarted on it's own - so the computer is now on and will have a log. If the logs have been wiped, that would also be evidence of tampering.
 
Old 06-15-2004, 03:52 PM   #10
Lechium
Member
 
Registered: Jun 2004
Distribution: Gentoo
Posts: 102

Original Poster
Rep: Reputation: 16
That's wierd... /var/log/syslog, xdm.log and others are empty, and dmesg goes as far as start of current uptime... creepy.. not shure who would want to hack me...
 
Old 06-15-2004, 03:54 PM   #11
XavierP
Moderator
 
Registered: Nov 2002
Location: Kent, England
Distribution: Debian Testing
Posts: 19,192
Blog Entries: 4

Rep: Reputation: 475Reputation: 475Reputation: 475Reputation: 475Reputation: 475
I'm going to move this to Linux-Security. It seems (to my admittedly limited knowledge) that your box has been tampered with. Was your box running anything important?

One of the regulars there or the Moderator may be able to give you advice on what to do next. In the meantime, I would definitely familiarise myself with the stickied threads at the top of that forum.
 
Old 06-16-2004, 09:08 PM   #12
paeng16
Member
 
Registered: May 2004
Posts: 47

Rep: Reputation: 15
Smile

try rpm -Va and check for any changes in the binaries. Since the logs, as you say is not normal. Did you install Aide, Tripwire or some file checkers? these would certainly help. You can also look at the changes in Permissions if you have time.

FYI, Even if you dont have important files residing on your server. Hackers would tend to use you as a relay to attack other boxes. Specially when you have a fast BroadBand and high in resources.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
installing linux on a computer and use hard disk on another computer danrweki Linux - Newbie 8 11-16-2005 10:11 PM
Internet is slower on my win computer than on my linux computer eXor Linux - Networking 1 12-03-2004 08:58 AM
Can't copy files from an SCO Unix System V computer to a Linux computer gnppapas Linux - General 2 11-27-2004 01:39 PM
Why would a windows computer smoke a linux computer for download speed ? lostboy Linux - General 4 10-21-2003 05:20 PM
How can i portage Linux from computer with Celeron proc to computer with Pentium 166? gdi Linux - General 4 05-31-2003 01:11 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:18 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration