LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-09-2005, 08:25 PM   #1
sspiro
Member
 
Registered: Jun 2002
Location: Tampa, FL
Distribution: Debian Lenny
Posts: 39

Rep: Reputation: 15
Help! I think I have a virus on my Debian Server..




Still fairly new to linux, have been running a debian server for about 3 or 4 months to host some personal websites for myself and a family member or two.

I recently reformated my main PC (WinXP Pro) and obtained a virus shortly thereafter (few days ago) when I downloaded a questionable item (won't go into details)..This virus wrecked havoc on my main PC.. actually; it's been a nitemare. I never even thought it would infect my debian machine, and maybe it hasn't. Here are the details:

Upon checking free I see that I have 2% RAM left. Also I can't apt-get update, and I tried to install clamav, but I can't get that either..

SSH works...apache works..mysql works.. I can connect to the site through any of these services but the resources are blown out.

I don't have any active backups on this system (ARGHHhhhh) which is my fault.. But what are my options? Any thoughts on what is wrong with system? IS it in fact a virus or is it something else?
 
Old 03-09-2005, 08:51 PM   #2
comprookie2000
Gentoo Developer
 
Registered: Feb 2004
Location: Fort Lauderdale FL.
Distribution: Gentoo
Posts: 3,291
Blog Entries: 5

Rep: Reputation: 58
Anything interesting when you do a;
Code:
$ grep -i "failed password" /var/log/messages
 
Old 03-10-2005, 06:50 AM   #3
sspiro
Member
 
Registered: Jun 2002
Location: Tampa, FL
Distribution: Debian Lenny
Posts: 39

Original Poster
Rep: Reputation: 15
Absolutely nothing..

Quote:
spirowebserver:/# $ grep -i "failed password" /var/log/messages
bash: $: command not found
spirowebserver:/# grep -i "failed password" /var/log/messages
spirowebserver:/#
Update: I have been able to install clamav but it won't scan. I also have been able to get apt-get update to work also (not sure how, but it works now)...
 
Old 03-10-2005, 11:27 AM   #4
Paxmaster
Member
 
Registered: Jun 2004
Location: unknown place in NYC
Distribution: Ubuntu
Posts: 377

Rep: Reputation: 30
in the linux world the memory works very differnt way then in wndow world , just don't worry about
 
Old 03-10-2005, 05:30 PM   #5
sspiro
Member
 
Registered: Jun 2002
Location: Tampa, FL
Distribution: Debian Lenny
Posts: 39

Original Poster
Rep: Reputation: 15
Not worry about it? I can't even connect to the webserver when its running on 2% RAM left!

Needless I finally got ClamAV to scan and it detected and cleaned 4 viruses..Rebooted and I'm back down to about 35% RAM used.
 
Old 03-10-2005, 07:26 PM   #6
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
It's probably a good idea to download and run rootkit hunter on the system to identify any other hidden surprises on the system (rootkits, bindshells, etc).
 
Old 03-10-2005, 08:52 PM   #7
sspiro
Member
 
Registered: Jun 2002
Location: Tampa, FL
Distribution: Debian Lenny
Posts: 39

Original Poster
Rep: Reputation: 15
Quote:
Originally posted by Capt_Caveman
It's probably a good idea to download and run rootkit hunter on the system to identify any other hidden surprises on the system (rootkits, bindshells, etc).
Great suggestion. I was unfamiliar with that program until now..

Quote:
MD5
MD5 compared: 67
Incorrect MD5 checksums: 0

File scan
Scanned files: 342
Possible infected files: 0

Application scan
Vulnerable applications: 3

Scanning took 143 seconds
Even showed me some services I need to tighten up...

Thank you sir.
 
Old 03-10-2005, 09:18 PM   #8
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Quote:
Originally posted by sspiro
Great suggestion. I was unfamiliar with that program until now..
No problem. I'd also suggest looking into a file integrity scanner like tripwire, aide or samhain. They're really meant to be put on a system immediately after installation, so in this case they wouldn't be much help. But when used properly, they allow you to immediately detect modification of any critical system files and configs. In a situation like investigating a potential compromise or viral infection they can save you alot of time and grief.
Cheers.
 
Old 03-11-2005, 06:02 PM   #9
floppywhopper
Member
 
Registered: Aug 2004
Location: Western Australia
Distribution: Mageia , Centos
Posts: 643
Blog Entries: 2

Rep: Reputation: 136Reputation: 136
Just to clarify something .... please

Your Debian server had 4 viruses on it ???
or were you referring to your windows system

floppy
 
Old 03-11-2005, 07:02 PM   #10
tokyoeye
Member
 
Registered: Oct 2003
Location: Amsterdam
Distribution: gentoo,debian
Posts: 47

Rep: Reputation: 15
Could you maybe do a top to see what's eating all your RAM? When you're in top use M to see the memory usage. This could shed some light on what's causing the problem. If you see any processes you don't trust you can investigate the problem or give them a kill -9.
 
Old 03-14-2005, 04:27 AM   #11
apsivam
Member
 
Registered: Mar 2005
Location: Chennai, India
Distribution: Ubuntu, CentOS
Posts: 72

Rep: Reputation: 15
Quote:
Originally posted by floppywhopper
Just to clarify something .... please

Your Debian server had 4 viruses on it ???
or were you referring to your windows system

floppy
Nope those viruses reported by ClamAV were the virus test files that comes with ClamAV itself. More over ClamAV is a Virus Scanner ONLY not a remover.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Setting up a Debian proxy with firewall and virus protection ghanalinux Linux - Security 1 06-30-2005 09:43 AM
Anti Virus Server? Crashed_Again Linux - Software 7 02-01-2005 05:22 PM
Windows virus infection in debian yamakid Linux - Security 1 12-27-2004 07:06 PM
Boot virus or Anti-Virus? AVG Free Anti-Virus Software problems SparceMatrix Linux - Security 9 08-02-2004 02:35 PM
Ftp Server Virus Scanner rick_conlee Linux - Networking 1 03-01-2004 09:49 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:50 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration