Java Mailing List Archive

http://www.junlu.com/

Subjects
Home
mod jk2 https
Donation of JAXP 1 3 Sources to Apache
R annoyances
RE: Finding out when the aspnet admin worker process has recycled
Favorite Linux Distribution
eigenvalues of a circulant matrix
Apache Install
Reachin apache from outside
Ant should have an ext directory
Warning: Documentroot doesn 't exist
Can this be Done?
RE: Multilanguage Application
RE: Simple Question On setting up Sub Domain site
Lack of independence in anova()
How to close connection instead of sending 403?
winning the case for ANT
Re: adding php
New Ant GUI 'Ant 's Nest '
Narrowing Down A Strange Problem
Ant Task: sshexec
R Graph Gallery : categorization of the graphs
I 've been hacked, I need some help please
RE: Anyone working with DotNetNuke?
RE: Exception Handling Opinion
hex format
RE: IIS stopped working :(
<for > Build Failed:problem
RE: Separation of Objects from Logic
RE: Tracking pages with long request execution time
sending email to multiple destination
Web Site
ant UI
Easy cut & paste from Excel to R?
Win32 Apache Restart
Improving Tasks
HELP! PLEASE!
RE: Adding Controls to a Page
read table
RE: ASPNET account doesn 't exist!
Best way to uninstall Apache2 on red hat
from win to linux how to web page
XMLParseException changes and creation of XMLLocator2
Re Post: rewrite backslash to forward slash
Target or macrodef?
Page display problem XPSP2
Authentication problems
Dynamic Dictionary Data Type?
Newbie unable access my www from outside
off topic question: Latex and R in industries
Conflict between xtable and Hmisc when using Sweave?
Very old problem without any new solution
mod rewrite help
Basic Authentication question
RE: Code Security
calling ant from java program
prevent double signing
Re: Controlling Copy/Paste/Print
Using R to illustrate the Central Limit Theorem
web server slow too much slow
access to user directories
Links
Home
Official R Project Site
 
Search:  
Power your search with and, or, +, -, or "some phrase" operators.
I 've been hacked, I need some help please...

I 've been hacked, I need some help please...

2005-03-15       - By Paul
Reply:     1     2     3     4     5     6     7     8     9     10     >>  

I would be interested in what OS you were running Apache on and what
PHP scripts you thought were suspect.
On Tuesday, March 15, 2005, at 09:22  AM, Francisco Hidalgo Sol? wrote:

> Yes, I'm sure root only files were changed, as my
> complete log directory that is gone. Unfortunatelly,
> or fortunatelly, this is my home machine hosting some
> sites of friends, so I never worried that much for
> security, only the normal things. I wasn't doing
> remote logging either so I have no idea what happened.
> I came to the same conclussion as you and other
> people, I must reinstall everything to be sure. But
> this post is mainly an attempt to be able to discover
> what happened and if this was a security hole in this
> specific version of apache or any other thing. So I
> know what to do on my new installation.
> I will start with Ivan Barrera's suggestions, chrooted
> apache, mod_security maybe selinux, but this bothers
> me so much, since this is only my home machine and I
> don't want to spend that much time in it...
> The first thing is remote logging, since I use
> syslog-ng in all my machines this should be very easy.
> Thank's for all the answers, if you know anything more
> about what could have been the attack I would like to
> hear about it.
>
>
> --- Dennis Speekenbrink
> <d.g.speekenbrink@(protected)> wrote:
>> Hi,
>>
>> Please keep in mind that I'm not a security expert.
>>
>> Something about this says that they did not get root
>> access to the machine.
>> Are you absolutely sure that "root-only" files we're
>> changed?
>>
>> Reasons for my thinking are:
>> The rogue processes are running under the Apache
>> user (why not root?)
>> You can still log in. (usually root-exploits change
>> the root password
>> first thing, sadly speaking from my own experience)
>> The rogue processes are located in /tmp which is
>> world-writeable.
>> If access was gained through Apache, and it was
>> indeed running as an
>> un-priviledged user, then they would need a second
>> exploit to raise
>> their access level to root. By default a security
>> breach in apache
>> should only compromise anything that Apache can
>> touch.
>>
>> On the other hand:
>> If you're logged in and the 'who' command shows
>> absolutely nobody, then
>> it is obviously at fault.
>> If non-writeable files we're modified then an Apache
>> / php exploit alone
>> couldn't have done it.
>> If system logs we're deleted that is almost
>> certainly an indicator of a
>> root-exploit.
>>
>> If you conclude that root-access was indeed gained,
>> then the machine
>> must be considered lost.
>> Do not try to repair it, as you can never be sure
>> you removed all traces
>> of the attacker.
>> If you assume that it was only a apache / php
>> exploit then repair is
>> possible but a reinstall might be safer.
>>
>> Good luck!
>>
>> Dennis
>>
>> p.s. if you have an off-site backup or remote
>> logging try comparing data
>> to see what has changed.
>>
>>
>>
>>
>>
>>
> ---------------------------------------------------------------------
>> The official User-To-User support forum of the
>> Apache HTTP Server Project.
>> See <URL:http://httpd.apache.org/userslist.html> for
>> more info.
>> To unsubscribe, e-mail:
>> users-unsubscribe@(protected)
>>    "   from the digest:
>> users-digest-unsubscribe@(protected)
>> For additional commands, e-mail:
>> users-help@(protected)
>>
>>
>
>
>  
>
>  
>    
> ___________________________________________________________
> 250MB gratis, Antivirus y Antispam
> Correo Yahoo!, el mejor correo web del mundo
> http://correo.yahoo.com.ar
>
> ---------------------------------------------------------------------
> The official User-To-User support forum of the Apache HTTP Server
> Project.
> See <URL:http://httpd.apache.org/userslist.html> for more info.
> To unsubscribe, e-mail: users-unsubscribe@(protected)
>    "   from the digest: users-digest-unsubscribe@(protected)
> For additional commands, e-mail: users-help@(protected)
>


---------------------------------------------------------------------
The official User-To-User support forum of the Apache HTTP Server Project.
See <URL:http://httpd.apache.org/userslist.html> for more info.
To unsubscribe, e-mail: users-unsubscribe@(protected)
  "   from the digest: users-digest-unsubscribe@(protected)
For additional commands, e-mail: users-help@(protected)


©2008 junlu.com - Jax Systems, LLC, U.S.A.