LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-07-2010, 11:30 AM   #16
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600

Quote:
Originally Posted by maydaymayday View Post
unless anything else comes up that might benefit the community
We might be able to help you assessing things if you can make available information like system and daemon logs, (net-facing) software inventory (versions, configs, logs) and such. If that sounds interesting and you have time to spare you're invited to email me but please do not attach anything unrequested.
 
Click here to see the post LQ members have rated as the most helpful post in this thread.
Old 01-07-2010, 03:17 PM   #17
Web31337
Member
 
Registered: Sep 2009
Location: Russia
Distribution: Gentoo, LFS
Posts: 399
Blog Entries: 71

Rep: Reputation: 65
not surprised. you have a poor-coded CMS(probably was written by someone who never been on the net so don't know it is full of dangers), probably a cracker exploited a hole in that, then he gained permission to execute code(yet another mistake: to allow shell access) or BOFed PHP, then he BOFed kernel and he's root.
you still didn't provide us any details about your software and kernel versions. i can think of nothing else then the way i described. version of kernel means almost nothing: the thing is most important is not "what" but "when": when was the kernel built?
pastebin your process list also.

Last edited by Web31337; 01-07-2010 at 03:23 PM.
 
Old 01-07-2010, 05:26 PM   #18
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by Web31337 View Post
you have a poor-coded CMS(probably was written by someone who never been on the net so don't know it is full of dangers), probably a cracker exploited a hole in that, then he gained permission to execute code(yet another mistake: to allow shell access) or BOFed PHP, then he BOFed kernel and he's root.
You may or may not be right but without "evidence" your statement equals guesswork. That's not what we're after in the Linux Security forum. Please work with facts, not fiction.
 
Old 01-08-2010, 01:54 AM   #19
Web31337
Member
 
Registered: Sep 2009
Location: Russia
Distribution: Gentoo, LFS
Posts: 399
Blog Entries: 71

Rep: Reputation: 65
I know, sorry.
This is why I ask maydaymayday for more details: for me and other people here to stop play guessing game.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
my server has been compromised, what next? Kropotkin Linux - Security 15 08-27-2009 06:15 AM
Server Compromised? lss1 Linux - Security 7 12-16-2005 12:49 AM
Server Compromised? stlyz3 Linux - Security 6 09-07-2005 04:28 PM
Compromised: rebuilding questions (mail) nbier Linux - Security 1 09-05-2004 06:13 AM
Server was compromised, need help Asiana Linux - Security 3 06-02-2004 12:39 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:18 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration