LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-10-2006, 08:57 PM   #1
nevarlen
Member
 
Registered: Feb 2005
Distribution: Debian 3.x & Fedora Core 3, Debie on IBM Thinkpad
Posts: 68

Rep: Reputation: 15
Wondering if my machine is Comromised??


Hello All,
I have almost everything in place on my machine to prevent unauthorized access and so far everything has been great, meaning blocked all brute force attacks, kept the system up-to-date, etc..However I just noticed a home directory created in October 17 for a user called "goetz" who never logged in. Although there is only a temp folder under the directory, I am a little paranoid about this anonymous dir. I tried looking into almost every log file, I could not see anything. Strangely though everything under /var/log covers events from December through today.
I know it may be hard to tell, or very easy to tell, do you all think my machine had been compromised? If so, what can I do to confirm it.
Any help would be greatly appreciated..
 
Old 01-10-2006, 09:51 PM   #2
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Strangely though everything under /var/log covers events from December through today.
What about the older rotated logs like /var/log/messages.1 or /var/log/secure.1 ?

Although there is only a temp folder under the directory, I am a little paranoid about this anonymous dir
Anything in it? Make sure everything is normal and you don't have odd files like '...' or hidden files. Also what does 'find / -newer /home/goetz -user goetz' turn up?

Are there any other possible explanations, like other users/admins who could have added it? Have you installed any software around that time period?

Is there anything it the bash history of goetz?

Wrt to security, do you have a file alteration detector like tripwire or samhain installed on the system?
 
Old 01-10-2006, 10:32 PM   #3
nevarlen
Member
 
Registered: Feb 2005
Distribution: Debian 3.x & Fedora Core 3, Debie on IBM Thinkpad
Posts: 68

Original Poster
Rep: Reputation: 15
Thanks for the reply Capt_Caveman,
I am running on mandriva 10.2.
Details of log files are as follows:
-rw-r----- 1 root adm 4206 Jan 8 04:02 /var/log/auth.log.1.gz
-rw-r----- 1 root adm 2090 Jan 1 04:02 /var/log/auth.log.2.gz
-rw-r----- 1 root adm 8083 Dec 25 04:02 /var/log/auth.log.3.gz
-rw-r----- 1 root adm 4614 Dec 18 04:02 /var/log/auth.log.4.gz
-rw-r----- 1 root adm 7512 Dec 12 04:02 /var/log/auth.log.5.gz
-rw-r----- 1 root adm 180589 Jan 8 04:02 /var/log/boot.log.1.gz
-rw-r----- 1 root adm 175679 Jan 1 04:02 /var/log/boot.log.2.gz
-rw-r----- 1 root adm 175009 Dec 25 04:02 /var/log/boot.log.3.gz
-rw-r----- 1 root adm 147799 Dec 18 04:02 /var/log/boot.log.4.gz
-rw-r----- 1 root adm 176869 Dec 12 04:02 /var/log/boot.log.5.gz
-rw-r----- 1 root adm 20 Jan 8 04:02 /var/log/explanations.1.gz
-rw-r----- 1 root adm 20 Jan 1 04:02 /var/log/explanations.2.gz
-rw-r----- 1 root adm 123 Dec 25 04:02 /var/log/explanations.3.gz
-rw-r----- 1 root adm 20 Dec 18 04:02 /var/log/explanations.4.gz
-rw-r----- 1 root adm 757 Dec 12 04:02 /var/log/explanations.5.gz
-rw-r----- 1 root adm 251 Jan 1 04:02 /var/log/lastlog.1.gz
-rw-r----- 1 root adm 234700 Jan 8 04:02 /var/log/messages.1.gz
-rw-r----- 1 root adm 238741 Jan 1 04:02 /var/log/messages.2.gz
-rw-r----- 1 root adm 220320 Dec 25 04:02 /var/log/messages.3.gz
-rw-r----- 1 root adm 183026 Dec 18 04:02 /var/log/messages.4.gz
-rw-r----- 1 root adm 261550 Dec 12 04:02 /var/log/messages.5.gz
-rw-r----- 1 root adm 7540 Jan 8 04:02 /var/log/rpmpkgs.1.gz
-rw-r----- 1 root adm 7528 Jan 1 04:02 /var/log/rpmpkgs.2.gz
-rw-r----- 1 root adm 7528 Dec 25 04:02 /var/log/rpmpkgs.3.gz
-rw-r----- 1 root adm 7528 Dec 18 04:02 /var/log/rpmpkgs.4.gz
-rw-r----- 1 root adm 102 Sep 14 04:02 /var/log/scrollkeeper.log.1.gz
-rw-r----- 1 root adm 341 May 29 2005 /var/log/scrollkeeper.log.2.gz
-rw-r----- 1 root adm 3107 Jan 8 04:02 /var/log/secure.1.gz
-rw-r----- 1 root adm 965 Jan 1 04:02 /var/log/secure.2.gz
-rw-r----- 1 root adm 6511 Dec 25 04:02 /var/log/secure.3.gz
-rw-r----- 1 root adm 3854 Dec 18 04:02 /var/log/secure.4.gz
-rw-r----- 1 root adm 5020 Dec 12 04:02 /var/log/secure.5.gz
-rw-r----- 1 root adm 717233 Jan 1 04:02 /var/log/security.log.1.gz
-rw-r----- 1 root adm 711510 Dec 1 04:02 /var/log/security.log.2.gz
-rw-r----- 1 root adm 731439 Nov 1 04:02 /var/log/security.log.3.gz
-rw-r----- 1 root adm 258020 Jan 8 04:02 /var/log/syslog.1.gz
-rw-r----- 1 root adm 263086 Jan 1 04:02 /var/log/syslog.2.gz
-rw-r----- 1 root adm 240116 Dec 25 04:02 /var/log/syslog.3.gz
-rw-r----- 1 root adm 206025 Dec 18 04:02 /var/log/syslog.4.gz
-rw-r----- 1 root adm 289558 Dec 12 04:02 /var/log/syslog.5.gz
-rw-r----- 1 root adm 68 Jan 8 04:02 /var/log/urpmi.log.1.gz
-rw-r----- 1 root adm 452 Jan 3 04:02 /var/log/urpmi.log.2.gz
-rw-r----- 1 root adm 90 Dec 20 04:02 /var/log/urpmi.log.3.gz
-rw-r----- 1 root adm 658 Dec 7 04:02 /var/log/urpmi.log.4.gz
-rw-r----- 1 root adm 256 Jan 8 04:02 /var/log/user.log.1.gz
-rw-r----- 1 root adm 248 Jan 1 04:02 /var/log/user.log.2.gz
-rw-r----- 1 root adm 124 Dec 25 04:02 /var/log/user.log.3.gz
-rw-r----- 1 root adm 20 Dec 18 04:02 /var/log/user.log.4.gz
-rw-r----- 1 root adm 883 Dec 12 04:02 /var/log/user.log.5.gz
-rw-r----- 1 root adm 5910 Jan 1 04:02 /var/log/wtmp.1.gz

There is also security.log.4 which was created Oct 1,2005, but it only shows the world writable files.

As for goetz's home dir, ls -all /home/goetz give me:
drwxr-xr-x 3 goetz goetz 4096 Oct 17 21:57 ./
drwxr-xr-x 11 root root 4096 Oct 17 21:57 ../
-rw-r--r-- 1 goetz goetz 24 Oct 17 21:57 .bash_logout
-rw-r--r-- 1 goetz goetz 191 Oct 17 21:57 .bash_profile
-rw-r--r-- 1 goetz goetz 231 Oct 17 21:57 .bashrc
-rw-r--r-- 1 goetz goetz 3729 Oct 17 21:57 .screenrc
drwx------ 2 goetz goetz 4096 Oct 17 21:57 tmp/


As for other possible explanations:
I am the only admin on the machine, noone else could have created this.
As far as file alterations go, I have default tool that came with mandriva which notifies root for any alteration. Unfortunately, I stopped paying attention to these emails while ago. Now, when I searched for the emails around october, I am not able to see anything.
If we assume the worst case scenario, I may need to rebuild the system. What do you suggest the easiest way to migrate the existing mysql data(this is my only concern)?
Thanks again..
 
Old 01-10-2006, 10:40 PM   #4
nevarlen
Member
 
Registered: Feb 2005
Distribution: Debian 3.x & Fedora Core 3, Debie on IBM Thinkpad
Posts: 68

Original Poster
Rep: Reputation: 15
I forgot to add the result for
# find / -newer /home/goetz -user goetz
find: WARNING: Hard link count is wrong for /proc: this may be a bug in your filesystem driver. Automatically turning on find's -noleaf option. Earlier results may have failed to include directories that should have been searched.
find: /proc/5520/task/5520/fd/4: No such file or directory
find: /proc/5520/fd/4: No such file or directory
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
i'm just wondering sweet*amber Linux - Security 3 05-07-2004 09:21 PM
wondering how well this machine will run linux h00ligan Linux - Newbie 2 02-13-2004 12:53 AM
wondering what to do pearsonx4 Linux - Newbie 2 09-22-2003 09:01 PM
Just wondering wr3ck3d Linux - Software 3 05-01-2003 05:58 PM
!WONDERING!... something JUDOLIZARD Linux - Newbie 2 03-25-2002 07:32 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:45 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration