charliecreed
Verified User
- Joined
- Feb 26, 2006
- Messages
- 56
Hello,
Basiclay today I woke up as usal then see emails from my ISP showing my box send outgoing data to random IP's to try and infect a box.
I logged in and see thousands of process's of sshd running by apache username. loads were arround 5.00 Luckly It didnt kill the box due to the amount of power the box has itself.
I killed the sshd then booted it back up through webadmin, logged back in and load was down, The first thing I did was check the logs.
Here is what I found in /var/log/httpd/error_log:
[Wed Apr 19 00:11:04 2006] [notice] Apache/1.3.34 (Unix) mod_ssl/2.8.25 OpenSSL/0.9.7g PHP/4.4.2 FrontPage/5.0.2.2510 configured -- resuming normal operations
[Wed Apr 19 00:11:04 2006] [notice] suEXEC mechanism enabled (wrapper: /usr/sbin/suexec)
[Wed Apr 19 00:11:04 2006] [notice] Accept mutex: sysvsem (Default: sysvsem)
[Wed Apr 19 01:43:17 2006] [error] [client 127.0.0.1] File does not exist: /var/www/html/r57shell/version.php
sh: sysctl: command not found
sh: sysctl: command not found
sh: sysctl: command not found
sh: sysctl: command not found
loads of sysctl command not found. not going to paste all of them.
--01:44:13-- http://www.el-z.org/privat/ownz
=> `ownz'
Resolving www.el-z.org... 66.6.63.32
Connecting to www.el-z.org|66.6.63.32|:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 492,947 (481K) [text/plain]
0K .......... .......... .......... .......... .......... 10% 115.94 KB/s
50K .......... .......... .......... .......... .......... 20% 231.78 KB/s
100K .......... .......... .......... .......... .......... 31% 437.02 KB/s
150K .......... .......... .......... .......... .......... 41% 237.70 KB/s
200K .......... .......... .......... .......... .......... 51% 446.75 KB/s
250K .......... .......... .......... .......... .......... 62% 230.71 KB/s
300K .......... .......... .......... .......... .......... 72% 425.81 KB/s
350K .......... .......... .......... .......... .......... 83% 229.53 KB/s
400K .......... .......... .......... .......... .......... 93% 237.97 KB/s
450K .......... .......... .......... . 100% 295.69 KB/s
01:44:16 (246.62 KB/s) - `ownz' saved [492947/492947]
sh: sysctl: command not found
--01:45:13-- http://www.geocities.com/ijookeren/bind.txt
=> `bind.txt'
Resolving www.geocities.com... 66.218.77.68
Connecting to www.geocities.com|66.218.77.68|:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 6,439 (6.3K) [text/plain]
0K ...... 100% 43.52 KB/s
01:45:14 (43.52 KB/s) - `bind.txt' saved [6439/6439]
[Wed Apr 19 05:53:38 2006] [error] [client 127.0.0.1] File does not exist: /var/www/html/r57shell/version.php
( lots of that every so often )
That's all I have been able to digout so far. I downloaded the files which he downloaded. The ownz file has to be complied with gcc so I didnt look at it however the bind.txt shows what is going on
As it says in that file type ps -A to see if the process is up and there was one called ownz, I quickly killed that.
Then I did a few kernel updates to the box, then did some advanced iptable rules just incased he tried this again.
Iptables will fix it for the time being, but still I want to know how he did this and how to stop it from happening again.
if you have any ideas to check out different logs please reply and I'll paste you whats in them.
Also the system is using Ubuntu but basiclay Debian.
Thanks,
Charlie
Basiclay today I woke up as usal then see emails from my ISP showing my box send outgoing data to random IP's to try and infect a box.
I logged in and see thousands of process's of sshd running by apache username. loads were arround 5.00 Luckly It didnt kill the box due to the amount of power the box has itself.
I killed the sshd then booted it back up through webadmin, logged back in and load was down, The first thing I did was check the logs.
Here is what I found in /var/log/httpd/error_log:
[Wed Apr 19 00:11:04 2006] [notice] Apache/1.3.34 (Unix) mod_ssl/2.8.25 OpenSSL/0.9.7g PHP/4.4.2 FrontPage/5.0.2.2510 configured -- resuming normal operations
[Wed Apr 19 00:11:04 2006] [notice] suEXEC mechanism enabled (wrapper: /usr/sbin/suexec)
[Wed Apr 19 00:11:04 2006] [notice] Accept mutex: sysvsem (Default: sysvsem)
[Wed Apr 19 01:43:17 2006] [error] [client 127.0.0.1] File does not exist: /var/www/html/r57shell/version.php
sh: sysctl: command not found
sh: sysctl: command not found
sh: sysctl: command not found
sh: sysctl: command not found
loads of sysctl command not found. not going to paste all of them.
--01:44:13-- http://www.el-z.org/privat/ownz
=> `ownz'
Resolving www.el-z.org... 66.6.63.32
Connecting to www.el-z.org|66.6.63.32|:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 492,947 (481K) [text/plain]
0K .......... .......... .......... .......... .......... 10% 115.94 KB/s
50K .......... .......... .......... .......... .......... 20% 231.78 KB/s
100K .......... .......... .......... .......... .......... 31% 437.02 KB/s
150K .......... .......... .......... .......... .......... 41% 237.70 KB/s
200K .......... .......... .......... .......... .......... 51% 446.75 KB/s
250K .......... .......... .......... .......... .......... 62% 230.71 KB/s
300K .......... .......... .......... .......... .......... 72% 425.81 KB/s
350K .......... .......... .......... .......... .......... 83% 229.53 KB/s
400K .......... .......... .......... .......... .......... 93% 237.97 KB/s
450K .......... .......... .......... . 100% 295.69 KB/s
01:44:16 (246.62 KB/s) - `ownz' saved [492947/492947]
sh: sysctl: command not found
--01:45:13-- http://www.geocities.com/ijookeren/bind.txt
=> `bind.txt'
Resolving www.geocities.com... 66.218.77.68
Connecting to www.geocities.com|66.218.77.68|:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 6,439 (6.3K) [text/plain]
0K ...... 100% 43.52 KB/s
01:45:14 (43.52 KB/s) - `bind.txt' saved [6439/6439]
[Wed Apr 19 05:53:38 2006] [error] [client 127.0.0.1] File does not exist: /var/www/html/r57shell/version.php
( lots of that every so often )
That's all I have been able to digout so far. I downloaded the files which he downloaded. The ownz file has to be complied with gcc so I didnt look at it however the bind.txt shows what is going on
As it says in that file type ps -A to see if the process is up and there was one called ownz, I quickly killed that.
Then I did a few kernel updates to the box, then did some advanced iptable rules just incased he tried this again.
Iptables will fix it for the time being, but still I want to know how he did this and how to stop it from happening again.
if you have any ideas to check out different logs please reply and I'll paste you whats in them.
Also the system is using Ubuntu but basiclay Debian.
Thanks,
Charlie
Last edited: