![]() |
Possible hack attempt?
I received 168 of these e-mail while I was at work today:
Subject: Cron <root@server> chown root:root /tmp/r00t && chmod 4755 /tmp/r00t && rm -rf /etc/cron.d/core && kill -USR1 13559 Body: chown: cannot access `/tmp/r00t': No such file or directory Any ideas? |
I would say this does not look that good.
You could take a look at you cronjobs, check your system with rkhunter (http://www.rootkit.nl/projects/rootkit_hunter.html) Do you have any possible insecure webapplication like any forum (vb, wbb, phpbb) or a "cms" like mambo etc. by that a attempt like this could be executed on your machine? |
I have phpBB. I just got those e-mails for the first time today. I checked for the users logged in at the time of getting the e-mails and I was the only one logged in.
|
Code:
Rootkit Hunter 1.2.9 is running |
Code:
Rootkit 'Sin Rootkit'... [ OK ] |
This does not look good. You should rerun rkhunter with the --createlogfile as suggested in the output and check out in the logfile which rootkit files exactly had been found.
Which linux distribution do you use? |
I will re-run it and create a log file this time. I woke up to 609 of those same e-mails.
I wonder why it says r00t instead of root? Also, I'm using FC5. |
Also, I found these 2 TXT files in my /tmp/ directory. They look to me like worms of some sort.
http://www.plastikracing.net/m3r.txt http://www.plastikracing.net/ojo.txt |
After looking through the log, it looks like I've been "owned."
Code:
[root@server libsh]# ls -al |
If possible, you should reinstall the complete server or restore the complete server from a backup that was done before it got hacked. Otherwise you can never be 100% sure that your server is clean.
|
| All times are GMT +2. The time now is 05:38. |
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2013, vBulletin Solutions, Inc.