[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[no subject]



On Wed, 17 Mar 2004 23:33:17 -0500
"Nick Travis" <lists at wormfishin.com> wrote:

> Now that I've been comprimised, is my only safe option to reinstall?  I
> assume something else could have been hidden somewhere for future use?
> 
> Nick
> 
> ----- Original Message -----
> From: "Stephan Uphoff" <ups at tree.com>
> To: "Atlanta Linux Enthusiasts" <ale at ale.org>
> Sent: Wednesday, March 17, 2004 7:17 PM
> Subject: Re: [ale] Error messages
> 
> 
> >
> > Time to re-install from scratch.
> > Looks like a rpc.statd exploit.
> > Is this a Redhat 6.2 system or older ?
&gt; &gt; ( <a  rel="nofollow" href="http://www.securityfocus.com/bid/1480";>http://www.securityfocus.com/bid/1480</a> )
&gt; &gt;
&gt; &gt; Use a firewall !
&gt; &gt;
&gt; &gt; Stephan
&gt; &gt;
&gt; &gt; Nick Travis wrote:
&gt; &gt; &gt; I got an email from my ISP today saying that they think I have a virus
&gt; on my
&gt; &gt; &gt; network, The public IP address that they saw the traffic on is a linux
&gt; &gt; &gt; webserver(running red hat), I checked out my /var/log/messages and this
&gt; is
&gt; &gt; &gt; what I found:
&gt; &gt; &gt; Mar 15 04:02:00 web anacron[3212]: Updated timestamp for job
&gt; `cron.daily' to
&gt; &gt; &gt; 2004-03-15
&gt; &gt; &gt; Mar 16 04:02:01 web anacron[3732]: Updated timestamp for job
&gt; `cron.daily' to
&gt; &gt; &gt; 2004-03-16
&gt; &gt; &gt; Mar 16 06:09:49 web rpc.statd[362]: gethostbyname error for
&gt; &gt; &gt; ^X???^X???^Y???^Y???^Z???^Z???^[???^[???bffff750 8049710 8052c1868746567
&gt; &gt; &gt; 6274736f6d616e797265206520726f7220726f66
&gt; &gt; &gt;
&gt; &gt; &gt;     bffff718
&gt; &gt; &gt;          bffff719  bffff71a
&gt; &gt; &gt;
&gt; &gt; &gt; bffff71b~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~
&gt; &gt; &gt;
&gt; P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~
&gt; &gt; &gt; P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~
&gt; &gt; &gt;
&gt; P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~
&gt; &gt; &gt; P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~
&gt; &gt; &gt;
&gt; P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~
&gt; &gt; &gt; P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~
&gt; &gt; &gt;
&gt; P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~
&gt; &gt; &gt; P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P
&gt; &gt; &gt; Mar 16 06:51:26 web kernel: linsniffer uses obsolete
&gt; (PF_INET,SOCK_PACKET)
&gt; &gt; &gt; Mar 16 06:51:26 web kernel: eth0: Promiscuous mode enabled.
&gt; &gt; &gt; Mar 16 06:51:26 web kernel: device eth0 entered promiscuous mode
&gt; &gt; &gt; Mar 16 09:37:37 web kernel: neighbour table overflow
&gt; &gt; &gt; Mar 16 09:37:37 web last message repeated 9 times
&gt; &gt; &gt; Mar 16 09:38:37 web kernel: NET: 253 messages suppressed.
&gt; &gt; &gt; Mar 16 09:38:37 web kernel: neighbour table overflow
&gt; &gt; &gt; Mar 16 09:38:39 web last message repeated 9 times
&gt; &gt; &gt; Mar 16 09:38:45 web kernel: NET: 220 messages suppressed.
&gt; &gt; &gt; Mar 16 09:38:45 web kernel: neighbour table overflow
&gt; &gt; &gt; Mar 16 09:38:47 web kernel: NET: 962 messages suppressed.
&gt; &gt; &gt; Mar 16 09:38:47 web kernel: neighbour table overflow
&gt; &gt; &gt; Mar 16 09:38:52 web kernel: NET: 3353 messages suppressed.
&gt; &gt; &gt; Mar 16 09:38:52 web kernel: neighbour table overflow
&gt; &gt; &gt; Mar 16 09:38:57 web kernel: NET: 3638 messages suppressed.
&gt; &gt; &gt; Mar 16 09:38:57 web kernel: neighbour table overflow
&gt; &gt; &gt; Mar 16 09:39:02 web kernel: NET: 3482 messages suppressed.
&gt; &gt; &gt; Mar 16 09:39:02 web kernel: neighbour table overflow
&gt; &gt; &gt; Mar 16 09:39:07 web kernel: NET: 3524 messages suppressed.
&gt; &gt; &gt; Mar 16 09:39:07 web kernel: neighbour table overflow
&gt; &gt; &gt; Mar 16 09:39:12 web kernel: NET: 3526 messages suppressed.
&gt; &gt; &gt; Mar 16 09:39:12 web kernel: neighbour table overflow
&gt; &gt; &gt; Mar 16 09:39:17 web kernel: NET: 3525 messages suppressed.
&gt; &gt; &gt;
&gt; &gt; &gt; I continued getting these messages every 5 seconds until 3:30pm on the
&gt; 16th
&gt; &gt; &gt; and it suddenly stopped.  Has anyone seen this before?  According to the
&gt; log
&gt; &gt; &gt; file the last time someone logged in was the 14th, which was me, and I'm
&gt; the
&gt; &gt; &gt; only one with access to the system.  My ISP gave me the following log:
&gt; &gt; &gt;
&gt; &gt; &gt; Time Zone: UTC
&gt; &gt; &gt;
&gt; &gt; &gt; Event Date Time, Destination IP, IP Protocol, Target Port, Issue
&gt; &gt; &gt; Description, Source Port, Event Count
&gt; &gt; &gt;
&gt; &gt; &gt; EventRecord: 16 Mar 2004 20:01:47, 10.1.x.x, 6, 111, RPC Exploits, 3990,
&gt; 1
&gt; &gt; &gt;
&gt; &gt; &gt; EventRecord: 16 Mar 2004 19:59:28, 69.162.x.x, 6, 111, RPC Exploits,
&gt; 4699, 1
&gt; &gt; &gt;
&gt; &gt; &gt; EventRecord: 16 Mar 2004 19:57:50, 69.162.x.x, 6, 111, RPC Exploits,
&gt; 4766, 1
&gt; &gt; &gt;
&gt; &gt; &gt; EventRecord: 16 Mar 2004 19:26:16, 69.140.x.x, 6, 111, RPC Exploits,
&gt; 4730, 1
&gt; &gt; &gt;
&gt; &gt; &gt; EventRecord: 16 Mar 2004 18:05:04, 69.81.x.x, 6, 111, RPC Exploits,
&gt; 3428, 1
&gt; &gt; &gt;
&gt; &gt; &gt; EventRecord: 16 Mar 2004 16:53:43, 69.40.x.x, 6, 111, RPC Exploits,
&gt; 3267, 1
&gt; &gt; &gt;
&gt; &gt; &gt; EventRecord: 16 Mar 2004 15:19:00, 69.22.x.x, 6, 111, RPC Exploits,
&gt; 3433, 1
&gt; &gt; &gt;
&gt; &gt; &gt; Any thoughts would be greatly appriciated.
&gt; &gt; &gt;
&gt; &gt; &gt;
&gt; &gt; &gt;
&gt; &gt; &gt; Nick
&gt; &gt;
&gt; &gt;
&gt; &gt; _______________________________________________
&gt; &gt; Ale mailing list
&gt; &gt; Ale at ale.org
&gt; &gt; <a  rel="nofollow" href="http://www.ale.org/mailman/listinfo/ale";>http://www.ale.org/mailman/listinfo/ale</a>
&gt; &gt;
&gt; 
&gt; 
&gt; 
&gt; -- 
&gt; This message has been scanned for viruses and
&gt; dangerous content by MailScanner, and is
&gt; believed to be clean.
&gt; If you have any questions please contact nick at precisionmillworks.com
&gt; Mailscanner thanks transtec Computers for their support.
&gt; 
&gt; _______________________________________________
&gt; Ale mailing list
&gt; Ale at ale.org
&gt; <a  rel="nofollow" href="http://www.ale.org/mailman/listinfo/ale";>http://www.ale.org/mailman/listinfo/ale</a>


-- 

I used to be interested in Windows NT, but the more I see of it the more it
looks like traditional Windows with a stabler kernel. I don't find anything
technically interesting there. In my opinion MS is a lot better at making money
than it is at making good operating systems.  -- Linus Torvalds


</pre>
<!--X-Body-of-Message-End-->
<!--X-MsgBody-End-->
<!--X-Follow-Ups-->
<hr>
<!--X-Follow-Ups-End-->
<!--X-References-->
<ul><li><strong>References</strong>:
<ul>
<li><strong><a name="00651" href="msg00651.html">[ale] Error messages</a></strong>
<ul><li><em>From:</em> ups at tree.com (Stephan Uphoff)</li></ul></li>
<li><strong><a name="00653" href="msg00653.html">[ale] Error messages</a></strong>
<ul><li><em>From:</em> lists at wormfishin.com (Nick Travis)</li></ul></li>
</ul></li></ul>
<!--X-References-End-->
<!--X-BotPNI-->
<ul>
<li>Prev by Date:
<strong><a href="msg00653.html">[ale] Error messages</a></strong>
</li>
<li>Next by Date:
<strong><a href="msg00657.html">[ale] [OT] Writing a parser</a></strong>
</li>
<li>Previous by thread:
<strong><a href="msg00653.html">[ale] Error messages</a></strong>
</li>
<li>Next by thread:
<strong><a href="msg00658.html">[ale] Error messages</a></strong>
</li>
<li>Index(es):
<ul>
<li><a href="maillist.html#00654"><strong>Date</strong></a></li>
<li><a href="threads.html#00654"><strong>Thread</strong></a></li>
</ul>
</li>
</ul>

<!--X-BotPNI-End-->
<!--X-User-Footer-->
<!--X-User-Footer-End-->
</body>
</html>