I suffered a crack [RedHat4.1] & I don't know how..

I suffered a crack [RedHat4.1] & I don't know how..

Post by Alessandro Forghier » Mon, 12 Jan 1998 04:00:00



Hello, everybody.
One of my machines was cracked recently. No major damage was done,
however, I have so far been unable to understand what hole has been exploited,
and this bugs me to no end.

It looks like the cracker is sending some sort of signal to either
telnetd or login...

If anybody has an idea, based on the info appended below, I will really
appreciate to hear about it...

Cheers,
        Alessandro Forghieri

This is how it all starts [I have changed hostnames & IP addresses in what
follows ]:

file: /var/log/secure:
Jan 10 07:34:38 foobar in.telnetd[8473]: connect from 10.0.98.9
Jan 10 07:35:33 foobar in.telnetd[8480]: connect from 10.0.97.152
Jan 10 07:35:47 foobar in.telnetd[8483]: connect from 10.0.97.152
Jan 10 07:38:49 foobar in.telnetd[8506]: connect from 10.0.97.152
Jan 10 07:39:17 foobar in.ftpd[8512]: connect from 10.0.97.152
Jan 10 07:42:54 foobar in.telnetd[8534]: connect from 10.0.97.152
Jan 10 07:43:06 foobar in.telnetd[8540]: connect from 10.0.98.9
Jan 10 07:43:28 foobar in.telnetd[8548]: warning: can't get client address: Connection reset by peer
Jan 10 07:43:28 foobar in.telnetd[8548]: connect from unknown
[...]

file: /var/log/messages:
Jan 10 07:34:41 foobar telnetd[8473]: ttloop:  peer died: Unknown error
Jan 10 07:35:54 foobar su:  on /dev/ttyp1
Jan 10 07:39:27 foobar ftpd[8512]: FTP LOGIN FROM ntsvr5-24.idirect.com [10.0.97.152], liquid
Jan 10 07:39:46 foobar ftpd[8512]: FTP session closed
Jan 10 07:40:33 foobar su:  on /dev/ttyp0
Jan 10 07:40:51 foobar linux: eth0: Transmitter access conflict.
Jan 10 07:40:51 foobar kernel: eth0: Transmitter access conflict.
Jan 10 07:41:21 foobar linux: eth0: Transmitter access conflict.
Jan 10 07:41:21 foobar kernel: eth0: Transmitter access conflict.
Jan 10 07:41:51 foobar linux: eth0: Transmitter access conflict.
Jan 10 07:42:22 foobar linux: eth0: Transmitter access conflict.
Jan 10 07:42:22 foobar kernel: eth0: Transmitter access conflict.
Jan 10 07:43:23 foobar su:  on /dev/ttyp3

---
Alessandro Forghieri            Site administrator Nouvelle srl

Via Giardini 460                Fax:    +39 59 343822

 
 
 

I suffered a crack [RedHat4.1] & I don't know how..

Post by Ivo Naninc » Wed, 14 Jan 1998 04:00:00


Hi,

I think it's time for you to recompile your kernel with some
firewall-options enbled and to install the ipfwadm tool.

Take a look at www.xos.nl...


> Hello, everybody.
> One of my machines was cracked recently. No major damage was done,
> however, I have so far been unable to understand what hole has been exploited,
> and this bugs me to no end.

--
Best regards, and don't let the bits byte!

Ivo Naninck.

 
 
 

I suffered a crack [RedHat4.1] & I don't know how..

Post by DeadButt the Terribl » Sat, 17 Jan 1998 04:00:00


mm, I remember seeing something at rootshell.com like this. I dunno if it
*does* this, it didn't work on my machine. in any case, I suggest you check
the redhat and linux alert lists.


Quote:> I think it's time for you to recompile your kernel with some
> firewall-options enbled and to install the ipfwadm tool.

firewalling wouldn't be a bad idea, either.


> > Hello, everybody.
> > One of my machines was cracked recently. No major damage was done,
> > however, I have so far been unable to understand what hole has been exploited,
> > and this bugs me to no end.

> --
> Best regards, and don't let the bits byte!
> Ivo Naninck.

--
 ___ _
| _ \ |_______ ___
| _ < / -_/ \_/ _ |
|___/_\___/_| \_  |
             /___/
 
 
 

I suffered a crack [RedHat4.1] & I don't know how..

Post by Poch Sen » Thu, 22 Jan 1998 04:00:00


Could it be a classic Spoof IP hijack on one of your trusted systems?

 
 
 

1. I don't need to know Apache, but I do need to know this...

I just want to set up my linux bow so I can write cgi's in perl and see
how they look in Netscape.

Things I've done:
1) Installed Apache

2) made sure the perl script was written correctly

3) added the line" ScriptAlias /home/httpd/cgi-bin/ /home/monotone/web"
to httpd.conf

4) tried to open the script as "hello" & "hello.cgi" with Netscape in
both of those directories

5) Made sure the http starts at boot-up

6) I even typed "httpd" at the prompt.

7) Made the script an executable with chmod

But the brouser still opens my scripts as a text file.

I'm out of ideas and every book I've seen assumes that I read the 14
chapters that came before the chapter on "cgi scripts".  What's the
quick and dirty solution?

Thanks in advance,
Tone Milazzo

Sent via Deja.com http://www.deja.com/
Share what you know. Learn what you don't.

2. CDE: Auto Repeat rate adjustable?

3. Got free Linux CD's -- don't know how to use 'em

4. Hauppauge WIN/PCI with bt878

5. Don't know how to set terminal 'dumb' to 8-bit...

6. what's wrong with ftp.netscape.com?

7. It's a viral, anti-american Pacman, don't you know?

8. Seraching for alternatives to a QLogic-SCSI-Controller

9. Don't really know what I'm doing (fstab/mtab settings)

10. HELP, I don't know what's wrong -- So simple

11. I don't know what's wrong

12. people who don't know their own URL's...

13. Windows for people who don't want to know why it doesn't work?