LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-15-2005, 02:10 PM   #1
ciscohead
Member
 
Registered: Mar 2003
Distribution: redhad 7.3
Posts: 42

Rep: Reputation: 15
rooted, can we salvage files


This friend of mine got rooted we think. She had an unpatched old RH 7.3 system and it had a iffy video card anyway and it wouldn't boot from any CDROM's any more so it wasnt being used much That's probably why she didn't upgrade it. then one day she turned it on, got on the internet and was running. She needed to do a su and the response was "segementation fault." yeah right. I don't think so. She quit aall apps, saved all files. She tried to shut it down with the software and it wouldn't let her. It kicked her back into her login. So she logged back in and checked to see if her files were still there. at that time they appeared to be OK. So she yanked power to the machine. After yanking the eth cable she later tried to cold boot and the cold boot hung. OK we think the kernel is probably toast and we don't care because we needed to upgrade anyway. But she would like to get the files, particularly the ones she just updated when she discovered the intrusion.

We removed the hacked hard drive and put it in another box and booted from a Knoppix CD. now the home directory for this user is showing up "locked" and we don't know how to get into it. Any ideas? What rootkit leaves this particular footprint?
 
Old 11-15-2005, 02:18 PM   #2
Alien Bob
Slackware Contributor
 
Registered: Sep 2005
Location: Eindhoven, The Netherlands
Distribution: Slackware
Posts: 8,559

Rep: Reputation: 8106Reputation: 8106Reputation: 8106Reputation: 8106Reputation: 8106Reputation: 8106Reputation: 8106Reputation: 8106Reputation: 8106Reputation: 8106Reputation: 8106
Why do you think she got rooted? To me, your story sounds like that of a computer with bad RAM.

And the "locked" folder? I think that is the GUI way of displaying that you cannot write there perhaps? Did you try a terminal and "ls -la" to check the contents?

Eric
 
Old 11-15-2005, 02:43 PM   #3
ciscohead
Member
 
Registered: Mar 2003
Distribution: redhad 7.3
Posts: 42

Original Poster
Rep: Reputation: 15
Bad RAM

and a bad video card AND both CDROM's not bootable.. what a P.O.S. eh? I'm not physically there right at the moment, so can't answer your question. But I think she knows enough to try ls -al. Would be nice if that's all it was.
 
Old 11-15-2005, 04:38 PM   #4
ciscohead
Member
 
Registered: Mar 2003
Distribution: redhad 7.3
Posts: 42

Original Poster
Rep: Reputation: 15
She just called back to report that she burned a CD of all her files. I don't know whether she was really rooted or not or why she couldn't get them or thought she couldn't. But she's wiping the drive now... so I guess it doesn't matter. and I got her set up with a new video card and some more RAM. Thanks. it's always a good day when data is saved.
 
Old 11-17-2005, 07:32 AM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
it's always a good day when data is saved.
It's common for some rootkits to try and piggyback on system binaries (like Knark and /sbin/init) so I sure hope "saved data" only means userfiles from /home, configfiles from /etc and logfiles from /var and not any system binaries. *If* a system got cracked system binaries should *not* be trusted and used, unless you've got an isolated (disconnected) sandbox to check stuff on.
 
Old 11-18-2005, 09:38 AM   #6
ciscohead
Member
 
Registered: Mar 2003
Distribution: redhad 7.3
Posts: 42

Original Poster
Rep: Reputation: 15
absolutely right

My friend was only interested in saving her original data. The system binaries were all old & out of date anyway and she hasinstall CD's for any software she really cares about.
She's a gimp artist so she had
mainly graphics and her normal emails bookmarks and stuff. Maybe the bad guys embedded steganography in her artwork, but I seriously doubt it.
 
Old 11-20-2005, 11:49 PM   #7
tkedwards
Senior Member
 
Registered: Aug 2004
Location: Munich, Germany
Distribution: Opensuse 11.2
Posts: 1,549

Rep: Reputation: 52
Just out of interest did she re-install to something more recent than RH7.3? Her unpatched RH7.3 will probably just get cracked again and I'm sure she'd appreciate the newer versions of GIMP that are in more modern distros such as Fedora, Mandriva or Suse
 
Old 11-21-2005, 12:31 AM   #8
ciscohead
Member
 
Registered: Mar 2003
Distribution: redhad 7.3
Posts: 42

Original Poster
Rep: Reputation: 15
absolutely

apparently she had tried to upgrade ages ago but her cdrom drive wouldn't boot the fc4 cd so she put it off. while I had it open i popped in a newer CD drive now shes happily bashing away
on fc4 and yes she does like the new gimp
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to salvage data from crippled LVM Kokuyo Linux - General 4 11-18-2005 12:04 PM
Hard disk failure, how to salvage? Worstje Linux - Hardware 3 04-25-2005 06:23 AM
What can be done to salvage a bad CD? vasudevadas Linux - Hardware 5 04-17-2005 11:34 PM
Have I been rooted? schteelhead Linux - Security 2 12-24-2004 08:46 PM
Linux to salvage windows? frkstein Linux - General 2 02-18-2002 11:52 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:35 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration