LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Closed Thread
  Search this Thread
Old 03-14-2007, 03:31 AM   #1
jovie
Member
 
Registered: May 2006
Posts: 54

Rep: Reputation: 15
Is this a compromised machine.


Could someone tell me if this behavior is like to be as a result of a hack and if so is there a better way of dealing with it than reformatting the hard drives and starting again with better security?

Symptoms
Disapearing disk space from the /var partition only. First noticed about 36hrs ago
Code:
[root@zs]# df -h
Filesystem            Size  Used Avail Use% Mounted on
...
/dev/hda6              48G   45G     0 100% /var
[root@zs]# du -sh /var
27G     /var
More details in my original question at <a href="http://www.linuxquestions.org/questions/showthread.php?t=537040"> Disk space - du and df discrepency</a>.

while /var/log/http/access_log was still being up dated /var/log/http/error_log last changed ~36 hrs ago and I would have expected a few php warnings to appear in there since then.
ssh connections refused, first noticed about 12hrs ago.
No unrecognized processes were seen running, no malicious damage to web pages and nothing unusual on any other partition, just /var.

I disconnect it from the network about 12 hrs ago so now we have no web server running. There are the usual failed logins in /var/log/secure but the successful ones (that remain in the log) are accounted for.

I read the first thing to do is make sure I'm in control of the machine. How can I do that if I don't know where the disk space went and what its being used for?

The data are backed up so a rebuild is not out of the question but I'd rather not do it if this has some other cause that I can fix.

Thanks for your opinions.
 
Old 03-14-2007, 04:18 AM   #2
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
You've opened a new thread asking the same question (granted, from a different angle) which you asked yesterday in the Linux - Newbie forum. If you feel this is a security issue, a more adequate approach would have been to ask a moderator to move your original thread to the Linux - Security forum (you can still do this). Why did you decide to not continue using your perfectly good original thread? In any case, this thread is being closed because posting a single thread makes it easier for members to help you and will keep the discussion in one place.

Discussion continues here: http://www.linuxquestions.org/questi...d.php?t=537040

Last edited by win32sux; 03-14-2007 at 04:54 AM.
 
  


Closed Thread



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Compromised? Jukas Linux - Security 6 12-06-2006 07:16 PM
Machine compromised, now have ports opened tvn Linux - Security 4 09-21-2005 03:04 AM
Machine compromised, now have ports opened tvn Fedora 1 09-13-2005 05:30 PM
Compromised machine delling81 Linux - Security 3 04-05-2005 10:20 PM
If I had a compromised machine... TheIrish Linux - Security 9 11-28-2003 01:31 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:58 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration