Welcome to Soft32 Linux Forums!
FAQFAQ    SearchSearch      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

lsof t0rn

 
   Soft32 Home -> Linux2 Arch -> Security RSS
Next:  Fedora 7 PPC failing to boot using yaboot (IBM pS..  
Author Message
Kirill Protsenko

External


Since: Jun 22, 2003
Posts: 1



(Msg. 1) Posted: Sun Jun 22, 2003 11:18 am
Post subject: lsof t0rn
Archived from groups: comp>os>linux>security (more info?)

Hello All,

This morning I had some problems on the server, so I started to
investigate and found out that libncurses.so.4 was missing... I
recently upgraded mysql from 3.53 to 4.0.13 but that was it!

Okay, I did ln -s libncurses.so.5.2 libncurses.so.4

This quick fix resolved some problems. Then I ran chkrootkit and found
out that some of the files are (might be) infected with t0rn... Which
might be no problem, because chkrootkit checks libncurses as far as I
know.

To make sure, I ran lsof, and no was no output at all. ls -la
/usr/sbin/lsof told me that a different user (other than root) owned
lsof... I downloaded a clean version of lsof, compiled, ran but the
output seemed usual, no suspicious files or ports.

Besides, the /usr/sbin/lsof had a "sia" set of attributes (which did
not allow root to unlink the file of top of that)... I changed that,
and replaced the suspicious binary with a freshly compiled one.

The question is: is it a hacker attack? or some buggy software??
(mysql?)

has anyone come across weird things like this?

regards
Kirill
Back to top
Login to vote
Michael Forster

External


Since: Jul 14, 2003
Posts: 33



(Msg. 2) Posted: Mon Jul 14, 2003 12:44 am
Post subject: Re: lsof t0rn [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Doug Laidlaw" <laidlaws DeleteThis @myaccess.com.au> wrote in message
news:s359u-lj3.ln1@dougshost.mydomain.org.au...
> >
> > ls, lsof, ifconfig, login, telnet, su, sudo, cron
> >
> > in the end I was able to locate them all and using the hd editing
software
> > (i can never remember the name - it took me a couple of weeks to find) I
> > ended up changing the flag value on the files inodes from $FF to $00
and
> > that then allowed me to delete the files normally.
> >
> > Mike.
>
> That has restored what you saw. What about the other things you haven't
> noticed? To repeat James: you have been cracked. The only way to get rid
> of all the damage is to do a fresh install from CD-ROMS, preferably after
a
> format of the drive. Keep a backup of ypur home directory to put back
> afterward.

Doug, I agree with you - those were the files that were wierd users and had
been patched so they didn't work at all, but once I had removed them I
copied over from another installation (on my laptop) Every file in the
master system dirs, /etc and below
/bin /sbin /usr/bin /usr/sbin /usr/local/bin /lib and recompile / install
the kernel and lilo, and I am currently installing afresh on a new machine
ready to swap the two over - while the system seems secure (and GRC also
agrees) I still don't trust it.

Mike
Back to top
Login to vote
Display posts from previous:   
Related Topics:
lsof information - Can anyone point me to some clearly written explanations of the output of lsof? Man lsof gives ather densely worded..

lsof -i gives error about uid 0xfffffffe - I just did lsof -i (trying it out after someone mentioned it in another thread). It lists all the open network sockets....

AIM, Yahoo Messenger, ICQ - Hello all, I am running all three services mentioned inthe subject line on a windows box and to test the security I a...

GPG: Invalid character - I decided that at long last I would start using gpg. During the gen-key, after I enter my real name, gpg complains with...

Reverse NAT and Masquerade Question - This is a network feasibility question. Do you know which of the following firewalls can perform a reverse address..

USER AUTHENTICATION FAILED - After installing openssh and perl-Net_SSLeay using webmin, I am not able to log in locally. I can only log in using..
       Soft32 Home -> Linux2 Arch -> Security All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum

Categories:
 Windows
 Linux
 Mac
 PDA


[ Contact us | Terms of Service/Privacy Policy ]