LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-11-2004, 07:25 AM   #1
vibhory2j
Member
 
Registered: Apr 2004
Location: India
Posts: 42

Rep: Reputation: 15
Linux Hacked!!!


Hello,

i think my linux box is hacked. i am having a RedhatLinux 7.3 installed. The problem is that someone has made some changes in startup/shutdown scripts so that whenever i shutdown linux, the system goes in to maintenance mode i.e runlevel 1. so accessing runlevel anybody could easily do anything with the system.

I tried to read the log files but didn't found anything. for instance to save my system i have also modified the script /etc/rc.d/rc so that whenever system goes into maintenance mode it asks for the root passwd.

I want to know how could someone having guest access do such a task of modifying the scripts. How can solve this problem and deny such activities in future.

Thanks in advance for help...
 
Old 10-11-2004, 08:06 AM   #2
320mb
Senior Member
 
Registered: Nov 2002
Location: pikes peak
Distribution: Slackware, LFS
Posts: 2,577

Rep: Reputation: 48
LQ Wiki

http://wiki.linuxquestions.org/wiki/Security

you've got some reading to do....so have fun
 
Old 10-11-2004, 10:05 AM   #3
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
First, try verifying the integrity of the init scripts using rpm -V <package> or just rpm -Va to verify them all. With the system going to run-level 1, only someone with local access would be able to use the machine, so you might want to think about who else has physical access to the machine. You should also take a look at the access logs (last and last -i) for abnormal access times, look at /etc/passwd for any abnormal users or users other than root with a UID of 0. You should also download and run chkrootkit or rootkit hunter to identify whether a rootkit has been installed (they have a tendency to bork the startup/shutdown files if they don't install properly).

In terms of how could this happen, Redhat 7.3 has not been supported for some time and unless youve been manually patching to keep up with recent security vulnerabilities, then there would be a number of local root exploits in the system that would allow a "privilege escalation" attack.
 
Old 10-11-2004, 02:30 PM   #4
hameedkhan
LQ Newbie
 
Registered: Oct 2004
Location: Karachi, Pakistan
Distribution: Slackware, SuSe, Ubuntu, CentOS
Posts: 19

Rep: Reputation: 0
Hi.
i think you are using shutdown command. to remind you shutdown command with no options and arguemtns will place you in single user mode. if you want to poweroff the system use 'shutdonw -h now' or if you want to use restart 'shutdown -r now'. for more information read 'man shutdown'

HTH,
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Linux hacked dan2006 Linux - Security 2 03-30-2005 07:06 PM
How did my linux-apache webserver get hacked? markie Linux - Security 18 10-19-2004 08:07 PM
How to know if a linux machine been hacked ? juanb Linux - Security 6 07-17-2004 04:44 AM
I suspect my linux server is hacked. What should i do ?? td0l2 Linux - Security 6 06-24-2004 04:13 AM
Linux System being hacked saravanan1979 Linux - Networking 5 06-13-2002 06:59 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:26 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration