My Linux box got cracked

My Linux box got cracked

Post by Rafae » Tue, 19 Sep 2000 23:28:30



Hello !
I know what happen. My computer was attacked. Files like login, ls,
portmap an ps
was substituted by scripts. Real files was founded on created folder by
intruder.

Can I follow who it was, or more precise from where it was. I am not
interesed to
find intruder but I would like to know where he is locate. If he is
dangerous.
What should I do? I work us NetworkAdministor and from this computer
(home) I was
login to work servers. I do not want cracker to find my password on this
servers.
What shell I do now?

Cheers
Rafael

 
 
 

My Linux box got cracked

Post by fogman4 » Sun, 31 Dec 1899 09:00:00


I would nuke the system and reinstall everything. Hope you have everything
backed up. Did you have a firewall on your machine or a firewall box between
your computer and whatever before this happened? And would change all your
passwords to whereever. Somebody else might be able to tell you how to trace
the person(s) that did this but to me it is not worth the time or effort. I
would also work on making your system more secure.

 
 
 

My Linux box got cracked

Post by Bit Twist » Sun, 31 Dec 1899 09:00:00


Any time your know a box is cracked, you should:
        pull the box off the network,
        save any data,
        save a full copy of the box for digital forensics,
        refomat disk drives and
        fresh install to remove any possible back doors the
        cracker installed.

Could go here to get an ipchains firewall script.
http://linux-firewall-tools.com/linux/firewall/index.html

You might want to read Armoring Linux
                http://www.enteract.com/~lspitz/linux.html
and             http://www.securityportal.com/lskb/articles/
and             http://www.securityportal.com/lasg/
and             http://www.cert.org/advisories/

Check on the vendor site for security updates to your distro.

On Mon, 18 Sep 2000 07:28:30 -0700, Rafael


>Hello !
>I know what happen. My computer was attacked. Files like login, ls,
>portmap an ps
>was substituted by scripts. Real files was founded on created folder by
>intruder.

>Can I follow who it was, or more precise from where it was. I am not
>interesed to
>find intruder but I would like to know where he is locate. If he is
>dangerous.
>What should I do? I work us NetworkAdministor and from this computer
>(home) I was
>login to work servers. I do not want cracker to find my password on this
>servers.
>What shell I do now?

--
The warranty and liability expired as you read this message.
If the above breaks your system, it's yours and you keep both pieces.
Practice safe computing. Backup the file before you change it.
Do a,  man command_here or cat command_here, before using it.
 
 
 

1. Getting only 30k/s from Win98 box behind a Linux IP masq box!!

        I have a Bell Atlantic (now Verizon! ;-)) Personal ADSL connection
and I'm using a Linux IP masquerading box to provide Internet connectivity
to my LAN of several Linux, Windows 98, and Windows 2000 boxen.  BA ADSL in
my area uses PPPoE instead of DHCP so I had to use the Debian pppoe package.
I also had to set the MTU setting of all the NICs on the boxen behind the IP
masq box to 1492 in order for them to work behind IP masq.  (For those
interested, I read something about PPPoE adding additional overhead to the
network packets and thus making the default MTU setting of 1500 too big ...
or something like that).  Setting the MTU to 1492 didn't seem to impact
performance though.  At least not on the Linux boxen.  FTPing a kernel tar
ball from ftp.kernel.org gave me about 50k/s to 60k/s (which is the kind of
throughput I get ftping from ftp.kernel.org directly on the ip masq box).
Not too shabby at all.  However, from the Windows 98 boxen I'm only getting
about 30k/s tops!!  Whats wrong here?  Am I to assume that Windows 98's
tcp/ip stack just sucks?  Or do I need to fiddle around with the settings
some more?  The settings I have for the Windows 98 boxen are: 1492 for the
MTU, 1452 for the MSS and 5808 for RWIN.

        Thanks in advance for any help with this!

---
===============================================================================
Arcadio A. Sincero Jr.
Computer Science Major at the University of Maryland Baltimore County,
Linux systems administrator, wanna-be Windows and Linux software developer,
amateur competitive bodybuilder and all-around nice guy.

WWW: http://www.sincero.com/~asincero (COMING REAL SOON NOW(tm)!)

"There are three kinds of people in this world: those who can count, and those
 who can't."

2. Gibberish in PINE on new install

3. Crack attempt on my Linux Box!!!

4. Maple V R3 and Slackware 2.3 (X11R6)

5. Warning, my linux box appears to have been cracked, symptoms follow

6. Q -- Adaptec AHA2940UW and aic7xxx SCSI drivers in 2.4.20

7. Crack attempt on my Linux Box!!!

8. CD-ROM support

9. Warning, my linux box appears to have been cracked, symptoms follow

10. Crack attempt on my Linux Box!!!

11. Cracked Linux Box

12. getting files from a windows 95 box onto an HP unix box