[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[cobalt-users] Been Hacked - WAS: Bad Data in /var/run/utmp



Well, add me to the list of people that's been comprismied by this BIND expoilt.. And DON'T think you're immune to this thing just because you have the BIND patch installed... I installed the patch one day after it was released, but apparently they had already gained some level of access previously... I also had none of the root kits mentioned here or any of the other *strange* directories as noted... I guess they weren't able to get full access, just enough to over-run the buffers and cause problems... The box was running Portsentry, Logcheck, IPChains, Telnet *disabled* - only SSH2 access, and *EVERY* patch listed on the Cobalt web site... Yesterday I started having strangeness when doing a "ps aux"... Everything was sorted by USERID instead of by PID <as usual>. Then when trying to do a top, I recv'd "Bad Data in /var/run/utmp"... So this morning I got on line with Cobalt, and flipped on Telnet to give them access and discovered you couldn't connect via Telenet --OR-- FTP... (But I could still get in via SSH2)... She said something about once they get in, they span the SSH daemon to get other connections <??>.. The only other difference I could find between this comprised box and my other two in operation... Under /var/run/ - the comprimed box had a strange syslog file... The two *uncomprised boxes run:

/var/run/syslogd.pid

But on the comprised box it was:

/var/run/syslog.pid

I won't even think about anything but a full wipe and OS restall.. But I tell you what.. when IPchains goes in this time, I'm putting up one MEAN FIREWALL that let's NO ONE in that box except via FTP <over SSH2> and WWW ports.... I'm sure I'll be running my firewall rules by the list in the coming day or so for any input on their config..

Keep watch closly.. and if you haven't already installed the BIND patch.. I'd go get it installed *right now*... <then take aim at CERT for releasing this madness on the net!>


_________________________________________________________________
Get your FREE download of MSN Explorer at http://explorer.msn.com