LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-20-2004, 06:17 AM   #1
dima1978
LQ Newbie
 
Registered: Sep 2004
Posts: 2

Rep: Reputation: 0
Apache - seems like I was hacked :-(


I saw THIS in my Apache log -

**************************************************
218.144.121.165 - - [10/Sep/2004:16:19:01 +0300] "GET http__soem_strange_url
218.144.121.165 - - [10/Sep/2004:16:19:01 +0300] "GET http__soem_strange_url
218.144.121.165 - - [10/Sep/2004:16:19:01 +0300] "GET http__soem_strange_
.............
.............

**************************************************

My www-pages on Apache CANNOT make these queries.
I think i'm hacked. 8-(((
I saw in logs - it was downloaded about 2 Gigs(!) from other sites!


What is it ???

Please HELP!!!!!!!!!!
What I have to fix ?????

My system -
Apache-AdvancedExtranetServer/2.0.47 (Mandrake Linux/6mdk) mod_perl/1.99_09 Perl/v5.8.1 mod_ssl/2.0.47 OpenSSL/0.9.7b PHP/4.3.2
 
Old 09-20-2004, 07:12 AM   #2
qwijibow
LQ Guru
 
Registered: Apr 2003
Location: nottingham england
Distribution: Gentoo
Posts: 2,672

Rep: Reputation: 47
i dont know about your specific problem... but the general steps you want to take are......

1) Run netstat.... make a note of any network programs that are running, but shouldnt be... make a note of any IP addressed connected to any ports that they shouldnt be.

2) Take the machine off the network, make any notes of anything usefull that may be lost after a re-boot. for example, are any porgrams running that shouldnt be,,, (ftp servers or http servers or telnet / ssh server ? especially on strange ports... Any changes made to your firewall ?

3) Shutdown...

4) Dont boot the machine, but boot a trusted OS like Knoppix (Live CD linux distro)
and use rkhunter or chrootkit to search for any root kits that may have been installed.

If you have been rooted, then the only cerain way to get rid of the problem is to do a format and clean install. (backup non executable and non config files)

when you get your machine back up, upgrade to the latest version of Apache...

Does your Server run Tripwire ? (if not then why not !!!)
from a knoppix session, chroot into the hacked hard drive and run "tripwire --check"

Does your server run Snort ? (if not then why not !!!)
is there anything interesting in the snort logs ?
 
Old 09-20-2004, 09:25 AM   #3
dima1978
LQ Newbie
 
Registered: Sep 2004
Posts: 2

Original Poster
Rep: Reputation: 0
I have been helped by another people!!

mod_proxy !!!!
 
Old 09-20-2004, 09:34 AM   #4
dominant
Member
 
Registered: Jan 2004
Posts: 409

Rep: Reputation: 30
Is that module vulnerable?
 
Old 09-20-2004, 04:31 PM   #5
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
There was a recent mod_proxy vuln with Apache 1.3, but it required a non-standard configuration (Apache had to be specifically setup to allow proxy requests, which is not the default configuration).

What you're likely seeing is someone attempting to locate an open proxy. This is fairly common and likely isn't much to be concerned about unless you're seeing large numbers of proxy requests. Though you should make sure that you've updated Apache recently (there was a mod_ssl vuln release for Mandrake last week).

Last edited by Capt_Caveman; 09-20-2004 at 04:32 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Apache entries - Hacked?? lawadm1 Linux - Security 2 11-27-2005 08:49 PM
Hacked or not? knutove1728 Linux - Security 3 11-21-2004 09:04 PM
How did my linux-apache webserver get hacked? markie Linux - Security 18 10-19-2004 08:07 PM
Apache 2 on Linux Red Hat 7.3: have I been hacked? Zingaro2002 Linux - Security 4 06-03-2003 11:37 AM
Hacked??? ajayn Linux - Security 7 02-28-2002 01:10 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:58 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration