LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-28-2005, 06:53 PM   #1
stefaandk
Member
 
Registered: Jun 2005
Distribution: Centos
Posts: 215

Rep: Reputation: 30
Exclamation Trying to indentify exploit.


Was getting these random crashes on our server but never was able to see things before they happened, so I kept my eye on top and then it showed up a process using 99% CPU run by apache called exe.

I did an lsof on the PID and it showed me this:

exe 28760 apache cwd DIR 9,2 4096 2 /
exe 28760 apache rtd DIR 9,2 4096 2 /
exe 28760 apache txt REG 9,2 17828 7914085 /tmp/upxBQEJWR4A2CV (deleted)
exe 28760 apache mem REG 9,2 106400 3686484 /lib/ld-2.3.2.so
exe 28760 apache mem REG 9,2 1539996 7782401 /lib/tls/libc-2.3.2.so
exe 28760 apache 0r CHR 1,3 132585 /dev/null
exe 28760 apache 1r CHR 1,3 132585 /dev/null
exe 28760 apache 2r CHR 1,3 132585 /dev/null
exe 28760 apache 3u IPv4 22411320 TCP myserver.com:46726->sv4.rapha.ac:3434 (ESTABLISHED)

THen the list continues with all my domains access_log files being open and ending with:

exe 28760 apache 1232w REG 9,2 0 2293915 /var/log/httpd/ssl_access_log
exe 28760 apache 1233w REG 9,2 0 2293916 /var/log/httpd/ssl_request_log
exe 28760 apache 1234u REG 9,2 0 7913686 /tmp/ZCUD7YqeMz (deleted)
exe 28760 apache 1235u sock 0,0 22410237 can't identify protocol
exe 28760 apache 1236u unix 0xecfeea40 22410238 socket

this sv4.rapha.ac is a japanese thing and I don't have japanese clients on my server really, but the subnet in iptables but I would like to know what it was and how it got onto my server?

Thanks
 
Old 12-28-2005, 08:11 PM   #2
Matir
LQ Guru
 
Registered: Nov 2004
Location: San Jose, CA
Distribution: Debian, Arch
Posts: 8,507

Rep: Reputation: 128Reputation: 128
If you have it still running, dumping the /proc/PID information for it might be useful as well. If you can get ahold of the binary, a disassembly may reveal more.
 
Old 12-28-2005, 08:41 PM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
I would like to know what it was and how it got onto my server
Next to undeleting and examining the file, find out what software people can interface with, check anything PHP or Perl related first, check your access/error logs.
 
Old 12-28-2005, 09:50 PM   #4
stefaandk
Member
 
Registered: Jun 2005
Distribution: Centos
Posts: 215

Original Poster
Rep: Reputation: 30
I can't actually find the file, there is no file called exe that's for sure. Tracing the process did not seem to give me an actual file that was running.
 
Old 12-30-2005, 09:39 AM   #5
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,659
Blog Entries: 4

Rep: Reputation: 3940Reputation: 3940Reputation: 3940Reputation: 3940Reputation: 3940Reputation: 3940Reputation: 3940Reputation: 3940Reputation: 3940Reputation: 3940Reputation: 3940
Judging from man lsof, I am not entirely persuaded that the string "exe" actually indicates the name of an intruder.

What other evidence do you have that an intrusion actually occurred here? Just to be sure, you know . . .
 
Old 12-31-2005, 12:28 PM   #6
enigmasoldier
Member
 
Registered: Jul 2003
Location: Florence, Ky
Distribution: CentOS 3.3-4, OpenBSD 3.3, Fedora Core 4, Ubuntu, Novell Open Enterprise Server
Posts: 213

Rep: Reputation: 30
You might want to check to see if you have a rootkit installed ASAP!
www.chkrootkit.org/
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
exploit checker linuxtesting2 Linux - Security 3 07-05-2009 02:15 PM
What exploit is this? Boss Hoss Linux - Security 6 06-11-2004 06:16 PM
EXPLOIT programmin darkseed2g3 Linux - Security 7 10-19-2003 09:31 AM
|more exploit Benamoz Linux - General 3 09-03-2003 04:59 AM
program to indentify graphics card rlpt Linux - General 3 08-31-2001 07:35 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:07 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration