LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-25-2010, 06:53 PM   #1
jmoschetti45
Member
 
Registered: Oct 2004
Location: Michigan
Distribution: Debian Squeeze (2.6.32-5)
Posts: 137
Blog Entries: 1

Rep: Reputation: 17
Signs of getting compromised


Today any web browser I use has randomly been brining me to http://www.xn--51haaaaaaa.com/ at random intervals.

I've run chkrootkit from a live cd, and rkhunter, clamav, f-prot, and bitdefender, nothing's unusual.

All the definitions were up to date.

I'm wondering if its possible that my router got hacked. I'm not sure this is even possible, but it's acting weird. Tried reflashing its firmware, didn't fix it.

I'm totally clueless...
 
Old 01-25-2010, 08:48 PM   #2
MrChilly0
Member
 
Registered: Jan 2007
Location: midwest USA
Distribution: gentoo w/ funtoo overlay
Posts: 146

Rep: Reputation: 23
that sever has some nice ports open:
PORT STATE SERVICE
21/tcp open ftp
23/tcp open telnet
25/tcp open smtp
80/tcp open http
110/tcp open pop3
135/tcp filtered msrpc
139/tcp filtered netbios-ssn
445/tcp filtered microsoft-ds
593/tcp filtered http-rpc-epmap
1720/tcp filtered H.323/Q.931

THe interesting port open from that site you gave is the tcp 593 port...that's for CIS which is for tunnelling...get your ip addy and use nmap and see what you've got open on your side...might give you clues on what to look for

Last edited by MrChilly0; 01-25-2010 at 08:53 PM.
 
Old 01-26-2010, 12:28 AM   #3
Web31337
Member
 
Registered: Sep 2009
Location: Russia
Distribution: Gentoo, LFS
Posts: 399
Blog Entries: 71

Rep: Reputation: 65
How "randomly". Describe it more clear, please, and which browsers you use. What URLs are you trying to visit, is there an URL which causes that all the time?
To be sure about router, scan it's ports from outside, if possible.
You can also try using different DNS server, say, google's ones.
2 MrChilly0: you see 135,139,445 etc as filtered. Probably they are blocked by your ISP(it's a common case), most ISPs block outgoing packets to those ports.
--upd:
www.xn--51haaaaaaa.com not resolving here.

Last edited by Web31337; 01-26-2010 at 12:34 AM. Reason: i can't find that server.
 
Old 01-27-2010, 09:39 PM   #4
jmoschetti45
Member
 
Registered: Oct 2004
Location: Michigan
Distribution: Debian Squeeze (2.6.32-5)
Posts: 137

Original Poster
Blog Entries: 1

Rep: Reputation: 17
Problem seems to have gone away. I nmap'd myself, nothing odd running, and nmap'd the router, nothing odd either.

Problem seems to have gone away.

Firefox, Epiphany, & Iceweasel all did it.

I got a good chuckle out of the port scan results from that server though...
 
Old 01-27-2010, 11:22 PM   #5
Web31337
Member
 
Registered: Sep 2009
Location: Russia
Distribution: Gentoo, LFS
Posts: 399
Blog Entries: 71

Rep: Reputation: 65
You know it can be back again, what would you do in that case?
From here it looks like DNS cache been poisoned but it's a guess. So you may wish to try using different DNS servers in case that will happen again. Say, google's ones, or local. I suppose you use your ISPs DNS. I personally use the one I run on the router and since I moved to it, I also have no troubles with regular work, our ISP's DNS is quite buggy, and perhaps our ISP is not the only one having this problem.
BTW, Iceweasel==Firefox if you didn't know
 
Old 01-28-2010, 05:45 PM   #6
jmoschetti45
Member
 
Registered: Oct 2004
Location: Michigan
Distribution: Debian Squeeze (2.6.32-5)
Posts: 137

Original Poster
Blog Entries: 1

Rep: Reputation: 17
Now using OpenDNS and its still gone. AT&T DNS fails apparently.

I have whatever version of Iceweasel is current in Lenny, and Firefox 3.6 manually installed.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Hello everybody - Clab signs in clab LinuxQuestions.org Member Intro 2 07-03-2008 06:47 AM
Signs Signs Everywhere Signs ....... dwcondu LinuxQuestions.org Member Intro 4 07-21-2007 01:14 PM
Bad disk signs.... svar Linux - General 1 11-14-2005 11:31 AM
Do you need one of these signs? xpression General 2 09-23-2005 11:59 AM
special signs missing ungua SUSE / openSUSE 19 11-27-2004 06:01 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:38 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration