LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-04-2004, 01:48 AM   #1
trubi
LQ Newbie
 
Registered: Jan 2003
Distribution: RedHat 7.3 (Valhalla)
Posts: 25

Rep: Reputation: 15
Hacked sshd, and can't delete it ?!?!


Hi

Our Server (RedHat 7.2) was somehow hacked via ftp , and the intruder just replaced sshd with his own, and the ssh and telnet are not available.
The Problem is that I can not delete his sshd to replace it with mine (working one)

It says to me that I do not have the priviligies to do this / The process is stoped and I'm root /

Any help and suggestions

Thanks in advance
 
Old 03-04-2004, 01:57 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Try to netstat and ps your processes for future reference, then drop to runlevel 1, this will kill users, daemon processes and network (the regular ones, not rogue processes). Use lsof to see what files are opened to get a grip on the location, and list your modules. If nothing insane turns up, then you prolly run a LKM. In any case it's now time to kill the box.


Kill the box and DO NOT power on again. Use a bootable cd like KNOPPIX, FIRE or PSK to investigate, or add the HD to another machine and mount readonly. If you need the box up, save the auth files and all logfiles, then make a dd copy for future reference. Make sure to wipe the WHOLE disk: repartition, reformat and reinstall from scratch. Don't copy over binaries or stuff that isn't human readable. Don't use a restore from backup unless you've got external (untampered) means of verifying the backup is sane.

Last edited by unSpawn; 03-04-2004 at 01:59 AM.
 
Old 03-04-2004, 09:05 PM   #3
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
The attacker probably changed the extended attributes on the sshd binary. IIRC you can do lsattr on the file to view it's extended attributes, and chattr to change them. There *should* be helpful man pages with more information on each of the above (or do $ apropos attributes).

Like unSpawn said, at this point you're going to have to reinstall the OS from scratch to make sure you really irradicate the cracker. There are simply too many other ways the system could be tampered with and back-doored, so the only way to be sure is to fdisk and reinstall.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to delete files that won't delete? di11rod Linux - Security 7 10-19-2005 09:14 PM
definitely being hacked---help!!! chongluo Linux - Security 10 12-01-2004 07:32 AM
Tried to delete file as root but it says I don't have permission to delete it! beejayzed Mandriva 23 03-12-2004 02:46 AM
Enabling SSH in mandrake 9.2 - sshd vs. sshd-xinetd DogTags Linux - Newbie 7 11-25-2003 12:17 PM
I have been hacked, please help .... nutecinc Linux - Security 5 01-04-2003 08:25 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:53 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration