LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-21-2003, 10:16 AM   #1
nuzzy
Member
 
Registered: Aug 2001
Location: New Hampshire, USA
Distribution: Ubuntu 6.06 LTS
Posts: 204

Rep: Reputation: 31
Someone logged into my machine?


I'm wondering if someone is remotely logged into my RH9 box. The reason I think this is that I'm seeing numerous e-mails being sent out. I have sendmail hardened to not allow relyaing and have confirmed this thru ordb.org, but yet I still see the mass mailings being sent out. Is there a way for me to check if someone else is using my machine or find out who it is??
 
Old 05-21-2003, 10:24 AM   #2
tcaptain
LQ Addict
 
Registered: Jul 2002
Location: Montreal
Distribution: Gentoo 2004 from stage 1 baby!
Posts: 1,403

Rep: Reputation: 45
I'm not sure which logs specifically (I'm not at my machine) but I'd look quickly in the /var/log directory...maybe in 'messages' or something...although there may be one called 'security' or 'secure'

You can also use the 'last' command.

If you think your box is sending out mass mailings, shut it down quick...or at least suspend sendmail til you are sure...I mean, its not nice to spam...especially if you are aware you are spamming.
 
Old 05-21-2003, 10:52 AM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Definately shut down sendmail, add an inbound LOG target rule to your firewall for TCP/25 and outbound for any/any. If your box has been used a lot you're bound to see some requests...

Determine how they where able to use your box. The "last" command will give you an account of who's been logged in, for example "last -ai10" will give you the ten most recent ones. If enabled, "lastb" should give you the last login failures. "w" or "who" show you who's on the box now.
Check the integrity of your binaries, libraries and configuration files using Aide, Samhain or tripwire (if installed), else you'll have to resort to verifying against your rpm database but that won't catch everything. Run chkrootkit, just to be sure. If anything fishy comes up, catch the output of 'ps axwww', 'netstat -anp' and 'lsof' to file and shut down your network connection. If all seems OK, start looking in /var/log/messages for "weird" entries anything with error, fail, fatal or pam in it, and /var/log/maillog(.*gz) for clues. If you find remote addresses, expect them to be temp accounts and/or connected tru proxies.

If you report back, please elaborate on what you've done to check and what you've found.
 
Old 05-24-2003, 12:40 PM   #4
nuzzy
Member
 
Registered: Aug 2001
Location: New Hampshire, USA
Distribution: Ubuntu 6.06 LTS
Posts: 204

Original Poster
Rep: Reputation: 31
Hi guys,

Thanks for your replies. I was one step ahead of your advice and shut down my SMTP when I saw mail being relayed from the unknown source. I did some investigating in my maillog and found out that the domain of attbi.com was being used to relay the mail. I'm an idiot because I had allowed that domain to relay because I use attbi.com. I wanted to run some tests using my home machine. I forgot to remove it from the relay when I was done, but I did and VIOLA! No problems for three days now.
 
Old 05-24-2003, 02:15 PM   #5
tcaptain
LQ Addict
 
Registered: Jul 2002
Location: Montreal
Distribution: Gentoo 2004 from stage 1 baby!
Posts: 1,403

Rep: Reputation: 45
you mean attbi.com was using YOUR open relay?
 
Old 05-24-2003, 03:17 PM   #6
nuzzy
Member
 
Registered: Aug 2001
Location: New Hampshire, USA
Distribution: Ubuntu 6.06 LTS
Posts: 204

Original Poster
Rep: Reputation: 31
AT&T themselves? No...it was someone@xxx.attbi.com using my SMTP to relay...
 
Old 05-24-2003, 05:11 PM   #7
2damncommon
Senior Member
 
Registered: Feb 2003
Location: Calif, USA
Distribution: PCLINUXOS
Posts: 2,918

Rep: Reputation: 103Reputation: 103
It's amazing.
I have been fooling around with some test runs of a home server.
People are always scanning, checking smtp, ftp, ssh, http, trying to exploit know hacks.
I am trying to learn to distinguish possible hits due to dynamic IP versus definate hack attempt.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
sharing internet from a windows 98 machine to a Red Hat Linux machine ritwiksolutions Linux - Newbie 7 03-14-2006 10:20 AM
running X applications on remote machine when logged in via ssh servnov Linux - General 1 08-15-2005 08:53 PM
kde much slower to start when logged in as alan than logged in as root arubin Slackware 0 04-26-2004 04:27 PM
mozilla works fine when logged in as a user but crashes when logged in as root jimi Linux - General 6 04-02-2003 08:34 PM
set daily time limit for being logged into machine? JustinHoMi Linux - General 1 10-15-2001 12:58 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:46 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration