Quote:> I received 2 e-mails yesterday from people telling me to stop hacking
> them, so I did some poking around. I've got a RedHat 6.1 box
*way* out of date. update to a recent version.
Quote:> as a firewall between my home network and my cable modem. It does DNS
> (BIND 8.2.1),
*way* out of date. update to a recent version.
do you own the cricket book (O'Reilly's _DNS and BIND_)? you should - if
you need DNS enough to run BIND, you can afford to get the book and read
it; if you can't afford the time and money for that, then you don't need
BIND enough to run it.
Quote:> www, pop3, imap,
why both pop3 *and* imap? get one or the other, and run it over SSL (or
run APOP only if SSL isn't an option); what possible reason for running
both?
Quote:> and was running telnet
no. don't. please tell me that was just a joke. there is *no* acceptable
reason for running telnet any longer. run ssh; run it with ssh2 as the
only enabled protocol.
Quote:> and ftp.
why exactly were you running www (apache) *and* ftp? are you *sure* you
couldn't have distributed whatever files you needed to distribute with
just one or the other? had you looked into that before you installed them
both? was ftpd running in a chroot jail?
Quote:> I noticed a lot
> of activity on my cable modem and ps revealed these processes:
> TTY COMMAND
> p0 -sh
> p0 sh ./r00t 163 25
> p0 ./scan 163 53 25
> p0 bash ./try 163.25.114.10
> p0 ./bind 163.25.114.10 -e
unplug the box from the network. NOW. back up user data, reformat the
harddisk, install a newer version of linux, lock down the services,
disable everything unneeded, try to get any update packages off the 'net
using another box and update, configure whatever is running for minimal
privileges and minimal access, restore user data, look over your new
firewall configuration _really_ _closely_, and only *then* consider
bringing it back online. please do not try to do this any other way.
Quote:> There's nothing of consequence in the messages file.
there wouldn't be. it would have been deleted. you have been rooted; do
as i outlined above.
Quote:> I disabled telnet in inetd.conf, sent a SIGHUP, verified that I could no
> longer telnet in, killed every ttyp0 process, and a few minutes later
> they were back.
yes, they would be. you have been rooted; do as i outlined above.
--
PGP/GnuPG key (ID 1024D/BFE0D6D0) available from keyservers everywhere
Key fingerprint = 3EBC 97FC 68AA 65F1 65E6 3D36 35F6 4213 BFE0 D6D0
"...life goes on
long after the thrill of living is gone..."