LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-21-2006, 02:27 PM   #1
winchester169
Member
 
Registered: Mar 2004
Posts: 31

Rep: Reputation: 15
outbound port 80


Hi, I have reason to believe that my security was recently compromised. THe following is from "last"

[root@halo ~]# last
root pts/1 c-24-22-148-xx.h Fri Jul 21 12:02 still logged in
root tty1 Fri Jul 21 12:01 still logged in
root pts/0 c-24-22-148-xx.h Fri Jul 21 11:42 - 12:04 (00:22)
reboot system boot 2.6.10-1.741_FC3 Fri Jul 21 11:40 (00:51)
root pts/0 c-24-22-148-xx.h Fri Jul 21 10:21 - down (01:16)
root pts/0 200.99.2.196 Fri Jul 21 05:41 - 05:48 (00:06)
root pts/2 acb52aef.ipt.aol Thu Jul 20 22:49 - 22:49 (00:00)
root pts/1 acb25e05.ipt.aol Thu Jul 20 22:29 - 00:53 (02:23)
root pts/0 acb37f3c.ipt.aol Thu Jul 20 22:10 - 00:35 (02:25)
bercea pts/0 89.32.130.43 Wed Jul 19 13:10 - 20:19 (07:09)
bercea pts/0 89.32.130.43 Wed Jul 19 11:57 - 12:51 (00:54)
bercea pts/0 89.32.130.43 Wed Jul 19 03:57 - 03:58 (00:00)
bercea pts/0 89.32.130.43 Tue Jul 18 23:48 - 02:00 (02:11)
root pts/1 c-24-22-148-xx.h Tue Jul 18 11:09 - 11:10 (00:00)
bercea pts/0 89.32.130.43 Tue Jul 18 05:26 - 11:24 (05:57)
root pts/0 c-24-22-148-xx.h Mon Jul 17 16:22 - 17:01 (00:39)
root pts/0 ac9eff5a.ipt.aol Sat Jul 15 10:36 - 10:37 (00:01)
bercea pts/0 89.32.130.43 Sat Jul 15 02:49 - 02:50 (00:00)
root pts/0 89.32.130.43 Fri Jul 14 14:35 - 14:37 (00:02)
root pts/0 89.32.130.43 Thu Jul 13 22:04 - 22:04 (00:00)
root pts/0 211.176.61.119 Thu Jul 13 21:49 - 21:50 (00:00)
root pts/0 c-24-22-148-xx.h Thu Jul 13 00:11 - 00:30 (00:19)
root pts/0 10.10.10.3 Wed Jul 12 12:07 - 12:08 (00:00)
root pts/0 c-24-22-148-xx.h Fri Jul 7 11:50 - 13:21 (01:30)
root tty1 Wed Jul 5 12:28 - down (15+23:08)


the connections from c-24-22-148-xx.h are me. The bercea is not nor are the aol connections. I removed the bercea account and I also changed the root password. Here are my problems now faced...


ps, netstat, pico and who knows what other commands are not available. I rsynced them from another server but I cannot connect to the internet from any machine on the network.

ping works, ssh works, ftp works, smtp,pop3,imap etc all work so those ports are allowing through traffic (both ways incedentally) I can connect to the webserver on this machine from itself and from all other machines on the network but absolutely no machine will connect to any other site on the outside and no outside machine will connect to this one on port 80.

how do i find out why port 80 is broken???
 
Old 07-21-2006, 03:32 PM   #2
Mara
Moderator
 
Registered: Feb 2002
Location: Grenoble
Distribution: Debian
Posts: 9,696

Rep: Reputation: 232Reputation: 232Reputation: 232
After your system is compromised you don't know which executables are yours. Unplug it from the Net, copy all your important data (which may be broken, btw, so also check backup...; it may be a good idea to compare with a number of backups). Reinstall. Period.

Put it online only after you have all patches installed and after checking the configuration.

I know it requires much time, but you don't seem to have another option.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Outbound URL Filtering matux Linux - Security 2 12-17-2005 03:21 AM
how do we find outbound port numbers mahanare Linux - Security 1 10-05-2004 12:32 PM
postfix outbound forwading? init Linux - Networking 4 08-26-2004 02:57 PM
snort logging all outbound traffic as port-scan? Pcghost Linux - Security 3 04-20-2004 01:12 PM
Outbound Firewall Collapse Linux - Software 2 04-14-2003 11:24 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:08 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration