LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-10-2005, 09:43 AM   #1
mikechao
LQ Newbie
 
Registered: Sep 2005
Posts: 1

Rep: Reputation: 0
log system hacked?


I found some illegal sshd entrances from unknow hosts.
I kill those connections, and try to evaluate my Fedora 4 box.

I found something strange...
First, I found the syslog daemon was stopped. So, I try to start it, and all those logs files seems well.

But I found the "/var/log/secure" was empty!!
Even I revise the setting in "/etc/syslog.conf", and the ssh connections still can't be logged into the "/var/log/secure" file.

Can anybody help me how to fix it??
 
Old 09-10-2005, 01:14 PM   #2
Half_Elf
LQ Guru
 
Registered: Sep 2001
Location: Montreal, Canada
Distribution: Slackware; Debian; Gentoo...
Posts: 2,163

Rep: Reputation: 46
Well... right now if you found illegal SSH connection, the first rule is SHUT DOWN SSHD. Like don't restart it again. The second rule would be to DISCONNECT the box from the network/internet. You have no idea what the intruder might have installed in the box so far.

Before fixing your logs, it would be very important to make sure there isn't any rootkit (modified binary) on your system or any trojans running. Install rkhunter or any rootkit finding tools and scan yourself. Then make sure no other system files ( starting by /etc/passwd ) have been modified.
But actually, if the attacker already modified your logging, you are probably fried already, it would probably be REALLY safer to reinstall the whole thing. Keeping a rooted box on the internet will only get you hacked again.
 
Old 09-14-2005, 08:40 AM   #3
vireshwali
Member
 
Registered: Sep 2005
Posts: 67

Rep: Reputation: 15
well
i agree with post2 above.
but i think you can fix this up again.
Before anything you need to check for rootkits and trojans on your box. Use rkhunter for that.
If damage is not much then try installing a port scanner on your box and a notifier also.
Copy the default config file for syslogd in your box (you can get it from net or some one else box)

change sshd port , root pass, disable root login, change pass for all users on your box.

if the damage is big its better to go off network and take a backup of your work and do a fresh install.

But before that make a log of all the files (can be just a find and grep) that were added or modified after the time the attack occured (or after the time you noticed the attack) and analyse the log for the users who modified these.

Its better to learn from this than to just run away from it......
 
Old 09-14-2005, 10:46 PM   #4
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
If the system was cracked and a rootkit installed on the system, then the *ONLY* way you can be reasonably sure that the system is secure is to do a full reinstall from trusted media. It can be extremely hard to track down all modifications that have been made to the system, especially without the aid of a file integrity scanner. A few relatively minor changes can completely compromise a system and it's even harder when someone is trying to hide their presence. I'd agree that doing some basic forensic analysis is probably a good idea.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
**HACKED** Snort log posted ghight Linux - Security 44 10-15-2004 12:48 AM
RH 8.0 system hacked sandalblady Linux - Security 4 07-03-2004 02:59 PM
Help, server hacked!!! how do i restore system binaries? abefroman Linux - Software 3 03-24-2004 05:52 PM
Linux System being hacked saravanan1979 Linux - Networking 5 06-13-2002 06:59 AM
System was hacked. I need advice on restoration... Mogwai Linux - Security 4 01-17-2002 11:39 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:16 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration