Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 01 Jan 1998 17:09:28 +0000
From:      "Þorður Ivarsson" <totii@est.is>
To:        Randy Katz <randyk@ccsales.com>
Cc:        questions@FreeBSD.ORG
Subject:   Re: HACKED (again)
Message-ID:  <34ABCDC8.FB4E4892@est.is>
References:  <Pine.BSF.3.91.971231174544.9098A-100000@ccsales.ccsales.com>

next in thread | previous in thread | raw e-mail | index | archive | help
Randy Katz wrote:
> 
> Ok,
> 
> Please help me out here. I shut off telnet to a particular host and had
> sshd & ftpd (wu beta 15) running with access only from one other host. The
> other host had telnetd running and ftpd.
> 
> They got into the host (let's call it host1) as root somehow and changed
> an index.html file of a Web Site (bragging). They erased their trail,
> blew away wtmp and any log entries...
> 
> The way I know they got in as root is .history in /root had entries of
> their activity.
> 
> The other host which could access this server via ssh had no sign of
> molestation that I can see. The log files and wtmp were completely in
> tact and no entries from anyone other then the intended (only 2 people
> log into this machine).
> 
> I WANT TO KNOW HOW THEY DID IT. Can anyone address this?
> 
> I'm NOT asking for a solution about what to do. I just want to know how
> they gained access. The machine is FreeBSD 2.2.5 the latest.
> 
> Thanx again,
> Randy Katz

We got attack from somone that screwed up everything on our system two
years ago. We tried to clean up the mess but few months later they
ruined our system completely. We spent all the time we could finding
vulnerable services, but I think they relinked most of the programs with
some sniffers that gave them all information needed any time they
needed.

My advice is to try everything out very thoroughly and act like the
crackers, and try everything out that I can find on the net that is said
exploit security holes. Do it on another system please, some research
system.

-- 
Þórður Ívarsson		Thordur Ivarsson
Rafeindavirki		Electronic technician
Norðurgötu 30		Nordurgotu 30
Box 309			Box 309
602 Akureyri		602 Akureyri
Ísland			Iceland

---------------------------------------------
Somtimes we have to find problem to the answer!
---------------------------------------------



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?34ABCDC8.FB4E4892>