PDA

View Full Version : Scary Stuff


dayjahone
9th September 2008, 16:54
I got an email from my ISP that said the following:

We've received the following complaint in regards to your account. It
indicates that one or more computers using the address space assigned
to your account are infected by a worm or virus, or that a server in
your IP space may have become rooted.

Such infections not only affect the performance of your computer, but
often use network resources to spread infection to other computers via
email. Other infections will allow your computer to participate in a
botnet for malicious use. Usually denial of service attacks against
other websites or false websites to gain credit card and other personal
information.
...

If you are running a server, please discuss this matter with your server
administrator or IT staff. Most rootkits will hide information such as
running processes and have been known to hide or completely alter system
logs to hide themselves.

Any way to check to see what the problem is?

Thanks.

sjau
9th September 2008, 18:10
I think that email is a hoax. Are you sure it's from ISP?

dayjahone
9th September 2008, 19:18
Yeah, it's legit. I called my ISP.

chipsafts
9th September 2008, 20:42
are you running a server?
if so, which email server program are you using?

dayjahone
9th September 2008, 21:28
Yes, I'm running a server set up according to the perfect setup. Postfix?

falko
10th September 2008, 18:32
Have you tried rkhunter and chkrootkit?
http://www.howtoforge.com/faq/1_38_en.html

dayjahone
11th September 2008, 06:29
chkrootkit seemed to work fine.

rkhunter gave me the following at the end:

MD5
MD5 compared: 0
Incorrect MD5 checksums: 0

File scan
Scanned files: 342
Possible infected files: 0

Application scan
Vulnerable applications: 0

Scanning took 97 seconds

However, rkhunter also gave me the following:

Determining OS... Unknown
Warning: This operating system is not fully supported!
Warning: Cannot find md5_not_known
All MD5 checks will be skipped!

and

* Filesystem checks
Checking /dev for suspicious files... [ OK ]
Scanning for hidden files... [ Warning! ]
---------------
/dev/.static
/dev/.udev
/dev/.initramfs
/dev/.initramfs-tools /etc/.pwd.lock
---------------
Please inspect: /dev/.static (directory) /dev/.udev (directory) /dev/.initramfs (directory)

edge
11th September 2008, 10:00
Are you running this server on a LAN with other computers in it?
If so. Are you sure that the server is the problem? It could also be othe PC's in your LAN.

dayjahone
13th September 2008, 06:14
It's linked to the machine's IP address.