LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-05-2005, 05:14 PM   #1
Mig21
Member
 
Registered: Jan 2005
Posts: 263

Rep: Reputation: 45
Possible breach


hello

i had some trouble upgrading packages on a slackware 10.1 box i installed yesterday. i looked in my /var/log/messages and luckily noticed this. i have no clue how it may have gotten there

is this the sgnature of a hacker or a bug in an application?

Code:
head -1500 messages | tail -100
gives me this: http://littlesvr.ca/misc/littlesvr-messages.txt

which is only mildly interesting, here's how it looks in a 111/43 char terminal

http://littlesvr.ca/misc/littlesvr-messages-1.png
http://littlesvr.ca/misc/littlesvr-messages-2.png
http://littlesvr.ca/misc/littlesvr-messages-3.png
http://littlesvr.ca/misc/littlesvr-messages-4.png

what an upgrade..

thanks
 
Old 07-05-2005, 07:07 PM   #2
Krugger
Member
 
Registered: Oct 2004
Posts: 229

Rep: Reputation: 30
That is kind of weird. What you got in your messages is the code of phpBB possibly version 2.0.12.

Now what it is doing in your messages I don't know. Maybe that is related to you upgrade problem.

Anyway if you want to check it out it is in includes/usercp_confirm.php.
 
Old 07-05-2005, 08:43 PM   #3
Mig21
Member
 
Registered: Jan 2005
Posts: 263

Original Poster
Rep: Reputation: 45
strange indeed. i have the latest phpbb on there (2.0.16) but php should write errors to the apache log. and this is not an error, it's possibly a buffer overflow.

oh i remember i forgot to restore my database and went to the forum site. maybe that's when it happened. but why the messages file?

anyway, false alarm.

cheers
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Gathering post breach information on linux xxx_anuj_xxx Linux - Security 3 11-12-2005 10:08 AM
Breach in Sendmail Security? bper Linux - Security 2 08-02-2005 05:40 PM
Network Security Breach nbjayme Linux - Security 0 03-17-2004 06:49 PM
HTTP access_log: security breach? lhoff Linux - Security 3 02-16-2002 11:10 AM
Security breach? lhoff Linux - Security 5 02-15-2002 01:33 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:44 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration