[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] Been Hacked - WAS: Bad Data in /var/run/utmp



At 05:59 PM 2/10/01 -0500, you wrote:

<SNIP>
patch listed on the Cobalt web site... Yesterday I started having strangeness when doing a "ps aux"... Everything was sorted by USERID instead of by PID <as usual>. Then when trying to do a top, I recv'd "Bad Data in /var/run/utmp"... So this morning I got on line with Cobalt, and flipped on Telnet to give them access and discovered you couldn't connect via Telenet --OR-- FTP... (But I could still get in via SSH2)... She said something about once they get in, they span the SSH daemon to get other connections <??>.. The only other difference I could find between this comprised box and my other two in operation... Under /var/run/ - the comprimed box had a strange syslog file... The two *uncomprised boxes run:

/var/run/syslogd.pid

But on the comprised box it was:

/var/run/syslog.pid

Last week, I had the same exact symptoms. Web pages served up nicely as per usual, but no POP, Telnet, or FTP connections were being accepted. Today, I looked at /var/run/ and saw a syslogd.pid dated (when I was able to boot the server and regain my lost services). I did a ps -aux and found the same thing: Instead of being listed by PID as usual, everything was listed by user.

I won't even think about anything but a full wipe and OS restall.. But I tell you what.. when IPchains goes in this time, I'm putting up one MEAN FIREWALL that let's NO ONE in that box except via FTP <over SSH2> and WWW ports.... I'm sure I'll be running my firewall rules by the list in the coming day or so for any input on their config..

Unfortunately, with the number of customers I have on this box, wiping the drive and reinstalling everything (not to mention getting all the domains, sites, and users back in working order) would require more downtime than I'm interested in having.

I have all my patches in place (I'm on a RAQ2) and I've looked through all the standard logs, etc. Is there anything specific I can look for to make sure someone's not running amok on my box? Any other unusual things anyone else has found on their RAQ lately?

Joe Colburn


-------------------------------------------------------------------------------------------------------------------------------
Free web space and email, profiles, postcards, auctions, etc: http://www.GotBlack.com