LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-28-2005, 06:19 AM   #1
dan2006
LQ Newbie
 
Registered: Mar 2005
Posts: 1

Rep: Reputation: 0
Linux hacked


We have a Redhat Linux v 7.2 system installed with cvsserver (also installed). Recently we put it into internet (telnet and rsh were disabled), however find it has been hacked meaning - system entered promiscuous mode, the passwd and other files has been modified. We are unable to access it locally or thorugh ssh.

Please advise in this regard how to find which files have been compromised/ changed! Please tell us how the intruder got thorugh and what must be done to prevent future occurence!
 
Old 03-28-2005, 06:31 AM   #2
Mega Man X
LQ Guru
 
Registered: Apr 2003
Location: ~
Distribution: Ubuntu, FreeBSD, Solaris, DSL
Posts: 5,339

Rep: Reputation: 65
No offense, but with Redhat 7.2 (which is really, really old and I bet it's also unpatched) even user Joe should be able to hack you. If you are running a server it's vital to use an up-to-date and patched system...

Unplug your network cords, backup your important files (if they were not destroyed), format and reinstall the system. If you cant login as root, use a LiveCD to chroot your partitions and make the backups. Make sure to make a secure system next time you build a server. Take a look into OpenBSD if you want something secure and running a server with older hardware (as I think you do, since you are running an old Redhat OS)

Good luck though...

Last edited by Mega Man X; 03-28-2005 at 06:32 AM.
 
Old 03-30-2005, 07:06 PM   #3
Krugger
Member
 
Registered: Oct 2004
Posts: 229

Rep: Reputation: 30
Some advisories on CVS from Redhat

FEDORA-2004-169: cvs
FEDORA-2004-170: cvs

RHSA-2003:012-07: Updated CVS packages available

mainly the double free bug
and some pserve related issues

and ifyou are not giving cvs access outright, maybe the ssh needed some updating as 7.2 isn't that up to date anymore.

RHSA-2002:043-10: Updated openssh packages available
RHSA-2002:127-18: Updated OpenSSH packages fix various security issues
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How did my linux-apache webserver get hacked? markie Linux - Security 18 10-19-2004 08:07 PM
Linux Hacked!!! vibhory2j Linux - Security 3 10-11-2004 02:30 PM
How to know if a linux machine been hacked ? juanb Linux - Security 6 07-17-2004 04:44 AM
I suspect my linux server is hacked. What should i do ?? td0l2 Linux - Security 6 06-24-2004 04:13 AM
Linux System being hacked saravanan1979 Linux - Networking 5 06-13-2002 06:59 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:36 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration