Java Mailing List Archive

http://www.junlu.com/

Subjects
Home
mod jk2 https
Donation of JAXP 1 3 Sources to Apache
R annoyances
RE: Finding out when the aspnet admin worker process has recycled
Favorite Linux Distribution
eigenvalues of a circulant matrix
Apache Install
Reachin apache from outside
Ant should have an ext directory
Warning: Documentroot doesn 't exist
Can this be Done?
RE: Multilanguage Application
RE: Simple Question On setting up Sub Domain site
Lack of independence in anova()
How to close connection instead of sending 403?
winning the case for ANT
Re: adding php
New Ant GUI 'Ant 's Nest '
Narrowing Down A Strange Problem
Ant Task: sshexec
R Graph Gallery : categorization of the graphs
I 've been hacked, I need some help please
RE: Anyone working with DotNetNuke?
RE: Exception Handling Opinion
hex format
RE: IIS stopped working :(
<for > Build Failed:problem
RE: Separation of Objects from Logic
RE: Tracking pages with long request execution time
sending email to multiple destination
Web Site
ant UI
Easy cut & paste from Excel to R?
Win32 Apache Restart
Improving Tasks
HELP! PLEASE!
RE: Adding Controls to a Page
read table
RE: ASPNET account doesn 't exist!
Best way to uninstall Apache2 on red hat
from win to linux how to web page
XMLParseException changes and creation of XMLLocator2
Re Post: rewrite backslash to forward slash
Target or macrodef?
Page display problem XPSP2
Authentication problems
Dynamic Dictionary Data Type?
Newbie unable access my www from outside
off topic question: Latex and R in industries
Conflict between xtable and Hmisc when using Sweave?
Very old problem without any new solution
mod rewrite help
Basic Authentication question
RE: Code Security
calling ant from java program
prevent double signing
Re: Controlling Copy/Paste/Print
Using R to illustrate the Central Limit Theorem
web server slow too much slow
access to user directories
Links
Home
Official R Project Site
 
Search:  
Power your search with and, or, +, -, or "some phrase" operators.
I 've been hacked, I need some help please...

I 've been hacked, I need some help please...

2005-03-15       - By Francisco Hidalgo Sol?
Reply:     1     2     3     4     5     6     7     8     9     10     >>  

OS, Gentoo Linux, recently upgraded (some days ago) to
the latest versions of what Gentoo developers consider
stable. The PHP scripts running, various versions of
phpBB, PHPmyadmin (secured), I think that there is a
PHPnuke there too...
I don't know the suspicios, but my brother instaled
some days ago a modification of the popular blog
software "world press", and he was with speed problems
in that script, everithing in my sites worked fine.
Now that I think of it, maybe thats the suspect number
one.


--- Paul <paul@(protected)> escribi??:
> I would be interested in what OS you were running
> Apache on and what
> PHP scripts you thought were suspect.
> On Tuesday, March 15, 2005, at 09:22  AM, Francisco
> Hidalgo Sol?? wrote:
>
> > Yes, I'm sure root only files were changed, as my
> > complete log directory that is gone.
> Unfortunatelly,
> > or fortunatelly, this is my home machine hosting
> some
> > sites of friends, so I never worried that much for
> > security, only the normal things. I wasn't doing
> > remote logging either so I have no idea what
> happened.
> > I came to the same conclussion as you and other
> > people, I must reinstall everything to be sure.
> But
> > this post is mainly an attempt to be able to
> discover
> > what happened and if this was a security hole in
> this
> > specific version of apache or any other thing. So
> I
> > know what to do on my new installation.
> > I will start with Ivan Barrera's suggestions,
> chrooted
> > apache, mod_security maybe selinux, but this
> bothers
> > me so much, since this is only my home machine and
> I
> > don't want to spend that much time in it...
> > The first thing is remote logging, since I use
> > syslog-ng in all my machines this should be very
> easy.
> > Thank's for all the answers, if you know anything
> more
> > about what could have been the attack I would like
> to
> > hear about it.
> >
> >
> > --- Dennis Speekenbrink
> > <d.g.speekenbrink@(protected)> wrote:
> >> Hi,
> >>
> >> Please keep in mind that I'm not a security
> expert.
> >>
> >> Something about this says that they did not get
> root
> >> access to the machine.
> >> Are you absolutely sure that "root-only" files
> we're
> >> changed?
> >>
> >> Reasons for my thinking are:
> >> The rogue processes are running under the Apache
> >> user (why not root?)
> >> You can still log in. (usually root-exploits
> change
> >> the root password
> >> first thing, sadly speaking from my own
> experience)
> >> The rogue processes are located in /tmp which is
> >> world-writeable.
> >> If access was gained through Apache, and it was
> >> indeed running as an
> >> un-priviledged user, then they would need a
> second
> >> exploit to raise
> >> their access level to root. By default a security
> >> breach in apache
> >> should only compromise anything that Apache can
> >> touch.
> >>
> >> On the other hand:
> >> If you're logged in and the 'who' command shows
> >> absolutely nobody, then
> >> it is obviously at fault.
> >> If non-writeable files we're modified then an
> Apache
> >> / php exploit alone
> >> couldn't have done it.
> >> If system logs we're deleted that is almost
> >> certainly an indicator of a
> >> root-exploit.
> >>
> >> If you conclude that root-access was indeed
> gained,
> >> then the machine
> >> must be considered lost.
> >> Do not try to repair it, as you can never be sure
> >> you removed all traces
> >> of the attacker.
> >> If you assume that it was only a apache / php
> >> exploit then repair is
> >> possible but a reinstall might be safer.
> >>
> >> Good luck!
> >>
> >> Dennis
> >>
> >> p.s. if you have an off-site backup or remote
> >> logging try comparing data
> >> to see what has changed.
> >>
> >>
> >>
> >>
> >>
> >>
> >
>
---------------------------------------------------------------------
> >> The official User-To-User support forum of the
> >> Apache HTTP Server Project.
> >> See <URL:http://httpd.apache.org/userslist.html>
> for
> >> more info.
> >> To unsubscribe, e-mail:
> >> users-unsubscribe@(protected)
> >>    "   from the digest:
> >> users-digest-unsubscribe@(protected)
> >> For additional commands, e-mail:
> >> users-help@(protected)
> >>
> >>
> >
> >
> >  
> >
> >  
> >    
> >
>
___________________________________________________________
> > 250MB gratis, Antivirus y Antispam
> > Correo Yahoo!, el mejor correo web del mundo
> > http://correo.yahoo.com.ar
> >
> >
>
---------------------------------------------------------------------
> > The official User-To-User support forum of the
> Apache HTTP Server
> > Project.
> > See <URL:http://httpd.apache.org/userslist.html>
> for more info.
> > To unsubscribe, e-mail:
> users-unsubscribe@(protected)
> >    "   from the digest:
> users-digest-unsubscribe@(protected)
> > For additional commands, e-mail:
> users-help@(protected)
> >
>
>
>
---------------------------------------------------------------------
> The official User-To-User support forum of the
> Apache HTTP Server Project.
> See <URL:http://httpd.apache.org/userslist.html> for
> more info.
> To unsubscribe, e-mail:
> users-unsubscribe@(protected)
>    "   from the digest:
> users-digest-unsubscribe@(protected)
> For additional commands, e-mail:
> users-help@(protected)
>
>  

__________________________________________________
Correo Yahoo!
Espacio para todos tus mensajes, antivirus y antispam ?gratis!
?Abr?? tu cuenta ya! - http://correo.yahoo.com.ar

---------------------------------------------------------------------
The official User-To-User support forum of the Apache HTTP Server Project.
See <URL:http://httpd.apache.org/userslist.html> for more info.
To unsubscribe, e-mail: users-unsubscribe@(protected)
  "   from the digest: users-digest-unsubscribe@(protected)
For additional commands, e-mail: users-help@(protected)


©2008 junlu.com - Jax Systems, LLC, U.S.A.