LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-18-2005, 10:57 AM   #1
di11rod
Member
 
Registered: Jan 2004
Location: Austin, TEXAS
Distribution: CentOS 6.5
Posts: 211

Rep: Reputation: 32
How to delete files that won't delete?


My server was comprimised this Saturday night by an attacker using an exploit against awstats. The intruder attempted to replace several binary files but only succeeded in knocking the computer completely off the network. I've removed all remnants of the intrusion with the exception of these two modified files--

/sbin/ifconfig
/sbin/init

Even as root I cannot delete these files. When I boot off the mandrake install disk in rescue mode, it doesn't mount the right drive for me to be able to mess with these files (that's just my own ignorance, not a complication of the intrusion).

I would reinstall the OS (Mandrake 10), but I've got too many custom settings for mail, web, web applications, database, that I don't want to have to recreate. That's why I'm attempting to manually fix this problem.

Any advice on this is greatly appreciated.

di11rod
 
Old 10-18-2005, 11:08 AM   #2
Gort32
Member
 
Registered: Sep 2004
Distribution: Slack!
Posts: 150

Rep: Reputation: 15
Bad idea. If someone that you don't trust has had root access for even only a few minutes, wipe the machine. Back up whatever settings you feel you need first, but you shouldn't let this box remain intact and dirty. If you don't wipe it every time there is a problem with the box this incident will lie in the back of your mind and bother you - did I really get everything off?
 
Old 10-18-2005, 11:25 AM   #3
di11rod
Member
 
Registered: Jan 2004
Location: Austin, TEXAS
Distribution: CentOS 6.5
Posts: 211

Original Poster
Rep: Reputation: 32
Gort,

I understand the importance of a clean wipe, but in this case, the downtime is killing me. I absolutely must get this system back online ASAP.

As for the risk that this box might do something sinister in the future, I've got logging on the physically isolated router that I can use to monitor its behavior.

di11rod
 
Old 10-18-2005, 11:39 AM   #4
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
di11rod,

I agree 100% with wiping this box clean and installing from scratch. I hear you on the downtime issue, but if you want to prevent future downtime you need to be completely sure you have removed the rootkit / bad software.

Before doing so take backups so that you have old data and a snapshot of system files that you will need in case you will be filing a law suit.
 
Old 10-18-2005, 01:16 PM   #5
Gort32
Member
 
Registered: Sep 2004
Distribution: Slack!
Posts: 150

Rep: Reputation: 15
If you do a good backup you should be able to wipe and have a working system within the hour. Tar up the entire /etc directory as well as the /home and /root directory if necessary. Grab /var but don't even try to use it to restore - just keep it on hand in case you need to glance at a log file or something. Only restore file by file to make sure that you don't get anything tainted. I've been there before - the peace of mind is completly worth the time.
 
Old 10-18-2005, 02:02 PM   #6
primo
Member
 
Registered: Jun 2005
Posts: 542

Rep: Reputation: 34
Try with "chattr -i /sbin/ifconfig /sbin/init"
 
Old 10-18-2005, 11:24 PM   #7
tkedwards
Senior Member
 
Registered: Aug 2004
Location: Munich, Germany
Distribution: Opensuse 11.2
Posts: 1,549

Rep: Reputation: 52
If the Mandrake rescue CD doesn't mount it by default then simply do:
Code:
mkdir /mnt/rootpartition
mount /dev/XXX /mnt/rootpartition
Now you should be able to access it
 
Old 10-19-2005, 09:14 PM   #8
di11rod
Member
 
Registered: Jan 2004
Location: Austin, TEXAS
Distribution: CentOS 6.5
Posts: 211

Original Poster
Rep: Reputation: 32
Thanks for these great tips. I'm heading into battle this evening!

I'll let you know how it goes. One way or another, I have to get this thing back online before 7:00 in the morning.

di11rod
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
delete files suguname Linux - Newbie 3 07-05-2005 08:49 AM
how do you delete files? otoomet Linux - General 6 11-12-2004 04:06 AM
Delete Files imsajjadali Red Hat 15 07-23-2004 01:12 PM
Tried to delete file as root but it says I don't have permission to delete it! beejayzed Mandriva 23 03-12-2004 02:46 AM
Delete Files bsengland Linux - Newbie 1 11-04-2002 05:29 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:21 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration