LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-06-2004, 03:26 AM   #1
Zi5
Member
 
Registered: Apr 2004
Posts: 35

Rep: Reputation: 15
My Fedora HACKED :( [Urgent]


Hello All ,
I have a server with cpanel in a Date Center so some hacker speak to me and he said i will hack your server in 2 days .
Today i recive this message from kernel but before im not recive it the message is
--------------------- ftpd-xferlog Begin ------------------------

TOTAL KB OUT: 38KB (0MB)
TOTAL KB IN: 302KB (0MB)

---------------------- ftpd-xferlog End -------------------------


--------------------- Kernel Begin ------------------------


WARNING: Kernel Errors Present
microcode: Error in the microcode...: 1Time(s)
microcode: error! Bad data in mic...: 1Time(s)

---------------------- Kernel End -------------------------


--------------------- ModProbe Begin ------------------------


Can't locate these modules:
char-major-188: 1 Time(s)

---------------------- ModProbe End -------------------------


Im too afrid of kernel message so i think i need to re install the kernel before the hacker hack my server
please help
 
Old 06-06-2004, 03:31 AM   #2
XavierP
Moderator
 
Registered: Nov 2002
Location: Kent, England
Distribution: Debian Testing
Posts: 19,192
Blog Entries: 4

Rep: Reputation: 475Reputation: 475Reputation: 475Reputation: 475Reputation: 475
If you think you have been cracked, your first step is to get the server off the network and off the internet.

Then, read here. This will give you reading material on hardening your security.

And please don't mark threads as "urgent", it doesn't mean that your problem will be seen any quicker and what is urgent to you is less so to the rest of us.
 
Old 06-06-2004, 04:03 AM   #3
Zi5
Member
 
Registered: Apr 2004
Posts: 35

Original Poster
Rep: Reputation: 15
Thanks you too much XavierP ,
The server not at my home .. this the problem .
Ok
Im just wanna to know how to disable perl from using on my webserver (only for websites not for local)
2.how to re-install kernel

Last edited by Zi5; 06-06-2004 at 04:15 AM.
 
Old 06-06-2004, 06:00 AM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
I have a server with cpanel in a Date Center so some hacker speak to me and he said i will hack your server in 2 days .
...which meant you had 2 days to go and do some prevention and install some detection.


Today i recive this message from kernel but before im not recive it the message is
ftpd-xferlog
TOTAL KB OUT: 38KB (0MB)
TOTAL KB IN: 302KB (0MB)

That's the FTP log and no errors can be seen from it. Who has access to service FTP? Are those users chrooted in their home? Are they allowed to execute/compile stuff there? Is /tmp on a separate partition? Is it mounted nosuid,noexec? (If noexec breaks server stuff, then make users have their $TMP within their $HOME and mount that nosuid,noexec). Any other services you run unprivileged user have access to?

Kernel
WARNING: Kernel Errors Present
microcode: Error in the microcode...: 1Time(s)
microcode: error! Bad data in mic...: 1Time(s)

Logwatch just noting the microcode "service" has errors. Disable that service unless you need it.


ModProbe
Can't locate these modules:
char-major-188: 1 Time(s)

Just Logwatch noting some module loading errors. 188 has to do with USB.
That's "alias char-major-188 off" in /etc/modules.conf to suppress this.


Im too afrid of kernel message so i think i need to re install the kernel before the hacker hack my server
please help

None of that as far as can be seen from Logwatch. What you'll want is to install a file integrity checker like Aide, Samhain or tripwire and cronjob it so you get regular reports on what changes on the system by mail. Normally this is done when the OS is installed and the system is in a pristine state. Before you install any, run your package manager in verify mode, then install and run chkrootkit(.org), Rootkit Hunter (rootkit.nl), Tiger (http://savannah.nongnu.org/projects/tiger/) and Bastille-Linux.
Correct the errors they mention and start your system hardening from there.

@Xav
If you think you have been cracked, your first step is to get the server off the network and off the internet.
I agree, (and nothing is easier to do like a "telinit 1" and let the colo ppl handle the rest) but for remote servers there's some considerations. If he did so only on the basis of these messages it would have seemed to be quite unnecessary.

Then, read here. This will give you reading material on hardening your security.
Wrong URI. Here's the LQ FAQ: Security references.

And please don't mark threads as "urgent", it doesn't mean that your problem will be seen any quicker and what is urgent to you is less so to the rest of us.
In the Linux - Security forum people are allowed to submit suspected breaches of compromise and classify it as "urgent" or whatever gets attention (provided it's a serious report and you don't violate the LQ Rules).
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Urgent...RTLinux on Fedora Core 3...Errors in Compiling kumarnine Linux - Software 2 09-19-2005 11:13 PM
Fedora Core Forum site down or hacked? maximalred General 2 01-15-2005 09:07 AM
Fedora Localhost login? URGENT munkey Fedora - Installation 7 11-08-2004 05:51 AM
Urgent: Being hacked right now. Actions? prell Linux - Security 15 10-04-2004 08:34 AM
urgent help needed on fedora cool_ashwin22 Fedora 7 09-16-2004 05:54 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:07 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration