LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-08-2003, 09:58 AM   #1
asktoby
Member
 
Registered: Jul 2003
Location: Cardiff, England ;)
Distribution: Mandrake 9.1
Posts: 94

Rep: Reputation: 15
Was I hacked?


I just re-booted my machine after leaving it online for about 24 hrs to find that there is a new user listed on the Mandy log in screen... "geogeek".

Has someone hacked me and set up their own user?

I'm not convinced that my root user has a password, you know. I used to type in a password to get to root, but it hasn't asked me for one since I upgraded Mandy 9.0 to 9.1. Just lets me into root no questions asked.

Advice?
 
Old 08-08-2003, 10:17 AM   #2
killi
Member
 
Registered: Apr 2003
Location: Norway
Distribution: Diff
Posts: 440

Rep: Reputation: 30
open a term and type su
passwd or not
and when logged in as root type passwd
and type new pass
edit /etc/passwd and delete the line that has geogeek in it and
you should consider to get a firewall
 
Old 08-08-2003, 10:23 AM   #3
asktoby
Member
 
Registered: Jul 2003
Location: Cardiff, England ;)
Distribution: Mandrake 9.1
Posts: 94

Original Poster
Rep: Reputation: 15
Thanks
I su'd to root, (no password required)
typed passwd, set a new passwd

That feels safer. Though when I look at /etc/passwd it is about 28 lines long with a line about geogeek at the end. The other lines mention things like postgres, named, postfix etc. I've deleted geogeeks line.

What's a good free firewall for mandrake 9.1 then? I use pccillin for my windows machine.
 
Old 08-08-2003, 11:48 AM   #4
killi
Member
 
Registered: Apr 2003
Location: Norway
Distribution: Diff
Posts: 440

Rep: Reputation: 30
firestarter shorewall there are lots of great ones out there
the classic though is iptables just do a little google search

cheers

erling
 
Old 08-08-2003, 02:50 PM   #5
asktoby
Member
 
Registered: Jul 2003
Location: Cardiff, England ;)
Distribution: Mandrake 9.1
Posts: 94

Original Poster
Rep: Reputation: 15
Very strange. No firewall yet but I have passworded root. - I then stepped away from the machine for about 2 hours and when I return an app calle KWrited is open with a document in it called
"Listening on Device /dev/pts/0"
and a few pages of

Message from syslogd@localhost at Fri Aug 8 07:53:59 2003 ...
localhost

Message from syslogd@localhost at Fri Aug 8 07:55:00 2003 ...
localhost

Message from syslogd@localhost at Fri Aug 8 07:56:01 2003 ...
localhost last message repeated 2 times

Message from syslogd@localhost at Fri Aug 8 07:58:00 2003 ...
localhost last message repeated 3 times

Message from syslogd@localhost at Fri Aug 8 07:59:49 2003 ...
localhost last message repeated 2 times

Message from syslogd@localhost at Fri Aug 8 08:01:00 2003 ...
localhost last message repeated 3 times

Message from syslogd@localhost at Fri Aug 8 08:02:01 2003 ...
localhost last message repeated 2 times

Message from syslogd@localhost at Fri Aug 8 08:04:00 2003 ...
localhost last message repeated 2 times

Message from syslogd@localhost at Fri Aug 8 08:06:00 2003 ...
localhost last message repeated 3 times

Message from syslogd@localhost at Fri Aug 8 08:07:59 2003 ...
localhost last message repeated 2 times

Message from syslogd@localhost at Fri Aug 8 08:09:00 2003 ...
localhost last message repeated 4 times

Message from syslogd@localhost at Fri Aug 8 08:10:59 2003 ...
localhost last message repeated 3 times

Message from syslogd@localhost at Fri Aug 8 08:12:00 2003 ...
localhost

Message from syslogd@localhost at Fri Aug 8 08:13:04 2003 ...
localhost last message repeated 4 times

Message from syslogd@localhost at Fri Aug 8 08:14:59 2003 ...
localhost last message repeated 2 times

Message from syslogd@localhost at Fri Aug 8 08:16:00 2003 ...
localhost last message repeated 3 times

Message from syslogd@localhost at Fri Aug 8 08:18:01 2003 ...
localhost last message repeated 2 times

Message from syslogd@localhost at Fri Aug 8 08:20:01 2003 ...
localhost last message repeated 2 times

Message from syslogd@localhost at Fri Aug 8 08:22:01 2003 ...
localhost last message repeated 3 times

Message from syslogd@localhost at Fri Aug 8 08:24:01 2003 ...
localhost last message repeated 2 times

Message from syslogd@localhost at Fri Aug 8 08:26:00 2003 ...
localhost last message repeated 3 times

Message from syslogd@localhost at Fri Aug 8 08:28:01 2003 ...
localhost last message repeated 2 times

...etc.

I wonder what they're up to?
 
Old 08-08-2003, 04:25 PM   #6
Jabber63
LQ Newbie
 
Registered: Aug 2003
Posts: 9

Rep: Reputation: 0
Isnt there a firewall on Mandrake 9.1 which you can setup?
 
Old 08-08-2003, 04:41 PM   #7
jailbait
LQ Guru
 
Registered: Feb 2003
Location: Virginia, USA
Distribution: Debian 12
Posts: 8,337

Rep: Reputation: 548Reputation: 548Reputation: 548Reputation: 548Reputation: 548Reputation: 548
The intruder has probably included more that just the geogeek password. You should go on an extermination campaign against geogeek. First try: find / -iname "*geogeek*" and see what turns up.
Similarly, you should learn as much about Kwrited as you can.

After you learn as much as you can about what has been inserted into your system then delete everything suspicious starting with the command:
userdel -r geogeek
If Kwrited is something that you do not use then exterminate it. If you do use it then reinstall it.

Also it is quite possible that someone has sent all of your passwords to a remote location. You should change all of your user names and all passwords and make all of the changes in as short a time interval as possible. If practical you should do the extermination and name changes while not connected to any network.

Last edited by jailbait; 08-08-2003 at 04:46 PM.
 
Old 08-08-2003, 05:36 PM   #8
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
The only piece of real advice is to reformat and reinstall.

Back up any HUMAN READABLE files you want to. No binaries. then reformat and reinstall. Make sure this time you put in the proper security measures and react on changes. If you think you're not up to securing/hardening your box, post in the Linux - Security forum after you reinstalled.
 
Old 08-09-2003, 04:17 AM   #9
MasterC
LQ Guru
 
Registered: Mar 2002
Location: Salt Lake City, UT - USA
Distribution: Gentoo ; LFS ; Kubuntu ; CentOS ; Raspbian
Posts: 12,613

Rep: Reputation: 69
Check your logs for info on "geogeeks" IP, you can always report em as well. Backup the /var if you have questions about that later, it'll likely be where your logs were located. This shouldn't be backed up to be re-inserted, but only for forensics at a later date.

Cool
 
Old 08-09-2003, 05:41 AM   #10
chr15t0
Member
 
Registered: Jun 2002
Location: London
Distribution: Slackware
Posts: 201

Rep: Reputation: 30
It seems rather pointless doing anything until you have set up your firewall/iptables... otherwise your intruder will just come back in. You need to do this in the right order. The first sensible thing would be to unplug your network cable.


christo
 
Old 08-09-2003, 05:47 AM   #11
Muddy
Member
 
Registered: May 2002
Location: Ohio
Distribution: Mandrake 9.2 Custom Kernel & Mythtv!
Posts: 256

Rep: Reputation: 30
personally I'd back up what you need wipe that sucker clean. I'd write all zero's to your HD then reinstall (offline) and after you have it all setup with a firewall inplace then put it back online.
 
Old 08-09-2003, 01:10 PM   #12
Strike
Member
 
Registered: Jun 2001
Location: Houston, TX, USA
Distribution: Debian
Posts: 569

Rep: Reputation: 31
Quote:
Originally posted by unSpawn
The only piece of real advice is to reformat and reinstall.

Back up any HUMAN READABLE files you want to. No binaries. then reformat and reinstall. Make sure this time you put in the proper security measures and react on changes. If you think you're not up to securing/hardening your box, post in the Linux - Security forum after you reinstalled.
Just thought I'd quote this again so it appeared again This is the best approach.
 
Old 08-09-2003, 05:14 PM   #13
andrewlkho
Member
 
Registered: Jul 2003
Location: London
Posts: 548

Rep: Reputation: 31
I agree. I would strongly advise you to do a backup of non-binary files [only if you need then], and /var for later examination, and then reinstall. get all security updates. Don't use the old username password that you used to. then connect to the internet ;-0. absolutely the best advice fron unspawn
 
Old 08-10-2003, 12:07 PM   #14
asktoby
Member
 
Registered: Jul 2003
Location: Cardiff, England ;)
Distribution: Mandrake 9.1
Posts: 94

Original Poster
Rep: Reputation: 15
Okay I'll take your advice and format the machine. Tsh, just as it was running nicely too!

First I need to get samba going so I can pull my files off (No CD-R, you see...)

Thanks all for the advice.
 
Old 08-13-2003, 01:32 PM   #15
asktoby
Member
 
Registered: Jul 2003
Location: Cardiff, England ;)
Distribution: Mandrake 9.1
Posts: 94

Original Poster
Rep: Reputation: 15
How's this for a plan of action then:
=========================
1-Log in as root. Type:
dd if=/dev/zero of=/dev/hda
(If I understand correctly, this will format my HD and write zeros across it.)

2-Boot machine with the Mandy9.1 CD inserted - install Mandy, choose "paranoid" when asked about security. (Will this stop p2p apps like gtk-gnutella, and other apps like aMSN working? Should I choose a lower security level?)

3-Choose a new root username/password.

4-Once Mandy is up and running, immediately run MandrakeUpdate and get all the patches.

5-Relax

Last edited by asktoby; 08-13-2003 at 01:33 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Have I been hacked? Please help linuxboy69 Linux - Security 11 09-07-2005 07:20 AM
Hacked? mikeshn Linux - Security 2 03-12-2004 01:57 PM
Help! Have I been hacked? Tenover Linux - Security 1 11-19-2003 03:24 PM
Did we just get hacked? vous Linux - Security 4 11-17-2003 08:11 AM
am i being hacked? tearinox Linux - Security 5 11-13-2003 06:00 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:52 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration