LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-25-2004, 02:11 PM   #1
linkety
LQ Newbie
 
Registered: Aug 2003
Posts: 2

Rep: Reputation: 0
Unhappy Newbie "thinks" his Fedora box may have been hacked


Smart People,

I'm still cutting my teeth on LInux and could use some help. I have Tripwire running on my Fedora box and I noticed some strange modifications after a recent integrity check. The files below had modifications to the inode number and write time, all between between 4am-5am this morning.

/usr/bin/newgrp
/usr/bin/newrole
/usr/bin/passwd
/usr/bin/screen
/usr/bin/xterm

Any idea where & how to start my investigation?

Thanks for any assistance you can provide!
 
Old 08-25-2004, 03:37 PM   #2
barisdemiray
Member
 
Registered: Sep 2003
Location: Ankara/Turkey
Distribution: Slackware
Posts: 155

Rep: Reputation: 30
- You can use rkhunter (http://freshmeat.net/projects/rkhunter/) and chkrootkit (http://www.chkrootkit.org/) to scan your machine against root-kits.
- You can check for any `new' and interesting ports that are listening.
- You can check for any `new' and interesting programs that are running.
- You can search for any strange commands in your shell history (if not deleted).
- You can look at the login logs or syslog messages.
- You can look at the /etc/passwd and /etc/group files for any newly created user accounts.
- You can try to reinstall these tools,.. and so on.

PS: Hackers don't attack you, crackers do. Please use the correct terms (RFC 1392)
 
Old 08-26-2004, 07:27 AM   #3
chrism01
LQ Guru
 
Registered: Aug 2004
Location: Sydney
Distribution: Rocky 9.2
Posts: 18,356

Rep: Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751
Are you sure you haven't got an auto-update running eg yum, apt ?
 
Old 08-26-2004, 03:30 PM   #4
linkety
LQ Newbie
 
Registered: Aug 2003
Posts: 2

Original Poster
Rep: Reputation: 0
I think you are right about the auto update. The day before I noticed the strange 4am changes, I did some updates with yum & synaptic. I noticed this morning (again between 4am-5am) that there were yet more changes flagged by Tripwire. Now I need to figure out how to disbale the auto update.

Thanks again, barisdemiray & chrism01!
 
Old 08-26-2004, 03:47 PM   #5
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
You're probably better off leaving auto-update on and just making a note as to when it's supposed to be run. You can normally just check the logs for YUM to see if the flagged package was indeed updated. By turning off auto-update you're much more likely to forget to install a critical security patch and leave yourself vulnerable.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Fedora Core 2: Screen Resolution can not change from "800X600" to "1024X 768" suhaimi_sj Fedora - Installation 18 12-17-2009 03:29 AM
newbie question: whats the difference between "su root", "su" and "su -&quo mojarron Slackware 9 12-07-2009 04:08 PM
Hacked by Paul "Rusty" Russell mnauta Linux - Security 14 11-15-2004 10:14 PM
"Newbie Here" just out of the box xtreem33 LinuxQuestions.org Member Intro 2 07-16-2004 05:30 PM
Can you change the "title" under your name that says "member" or "newbie&qu Whitehat LQ Suggestions & Feedback 3 11-19-2003 06:32 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:00 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration