[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[cobalt-users] Been Hacked - WAS: Bad Data in /var/run/utmp
- Subject: [cobalt-users] Been Hacked - WAS: Bad Data in /var/run/utmp
- From: "Craig Napier" <craignapier@xxxxxxxxxxx>
- Date: Sat Feb 10 15:09:27 2001
- List-id: Mailing list for users to share thoughts on Cobalt products. <cobalt-users.list.cobalt.com>
Well, add me to the list of people that's been comprismied by this BIND
expoilt.. And DON'T think you're immune to this thing just because you have
the BIND patch installed... I installed the patch one day after it was
released, but apparently they had already gained some level of access
previously... I also had none of the root kits mentioned here or any of the
other *strange* directories as noted... I guess they weren't able to get
full access, just enough to over-run the buffers and cause problems... The
box was running Portsentry, Logcheck, IPChains, Telnet *disabled* - only
SSH2 access, and *EVERY* patch listed on the Cobalt web site... Yesterday I
started having strangeness when doing a "ps aux"... Everything was sorted by
USERID instead of by PID <as usual>. Then when trying to do a top, I recv'd
"Bad Data in /var/run/utmp"... So this morning I got on line with Cobalt,
and flipped on Telnet to give them access and discovered you couldn't
connect via Telenet --OR-- FTP... (But I could still get in via SSH2)... She
said something about once they get in, they span the SSH daemon to get other
connections <??>.. The only other difference I could find between this
comprised box and my other two in operation... Under /var/run/ - the
comprimed box had a strange syslog file... The two *uncomprised boxes run:
/var/run/syslogd.pid
But on the comprised box it was:
/var/run/syslog.pid
I won't even think about anything but a full wipe and OS restall.. But I
tell you what.. when IPchains goes in this time, I'm putting up one MEAN
FIREWALL that let's NO ONE in that box except via FTP <over SSH2> and WWW
ports.... I'm sure I'll be running my firewall rules by the list in the
coming day or so for any input on their config..
Keep watch closly.. and if you haven't already installed the BIND patch..
I'd go get it installed *right now*... <then take aim at CERT for releasing
this madness on the net!>
_________________________________________________________________
Get your FREE download of MSN Explorer at http://explorer.msn.com