Security Basics mailing list archives

RE: security advice


From: "Andrei Popescu" <andrei.popescu () firstit ro>
Date: Wed, 25 Aug 2010 10:14:44 +0300

        Hello,
        I had something like this also.. I still have all the files, but in
my case the "hacker" just runned a CounterStrike server on my box. I have
found the exploit in a website that I host, it was an oscommerce and it had
a security issue in the pictures folder.. don't know how he had access but
the thing is he managed to reinstall openssh and somehow he got the root
password (not change it, I saw him logging in the box with my password, and
yes, the password was 18 characters, with letters and numbers and it didn't
mean anything).
        So as somebody already said. You should watch for web application in
general. I managed to secure the oscommerce app and now everything is ok. 


Best regards,
Andrei Popescu
IT Manager
Alttab Profit SRL
Tel: +4-0723.286.813
Fax: +4-021.210.33.65


------------------------------------------------------------------------
Disclaimer
The information in this email and any attachments may contain legally
privileged, proprietary and confidential information that is intended for
the addressee(s) only.  If you are not the intended recipient, you are
hereby notified that any disclosure, copying, distribution, retention or use
of the contents of this information is prohibited.  When addressed to our
clients or vendors, any information contained in this e-mail or any
attachments is subject to the terms and conditions in any governing
contract.  If you have received this e-mail in error, please immediately
contact the sender and delete the e-mail.

-----Original Message-----
From: listbounce () securityfocus com [mailto:listbounce () securityfocus com] On
Behalf Of Todd Haverkos
Sent: Tuesday, August 24, 2010 10:43 PM
To: Edmund
Cc: security-basics () securityfocus com
Subject: Re: security advice

Edmund <edmund () belfordhk com> writes:

I'm still very reprimanding myself for being
so careless. This is one lesson that I gotta
have imprinted in my thick skull.

Anyway, given this lesson,  can someone offer
any methodologies/programs that I can use to
protect the company system?   I'm now going
through the firewall rules to find out what
holes the intruder might have entered through.

Thanks.

Ed

First decide if you want a trained forensic investigator to
investigate the case. If so, don't touch the box and alter the
evidence any futher. 

If you don't have the budget or inclination for the above, Gold
standard of recovery would be to take a forensic image of that disk
(perhaps your deleted folder could be recovered from what's available
in slack at your leisure), and rebuild the server from original
optical media.... and ensure that patches are all up to date.

To determine how the compromise occurred would require the knowledge
of a trained forensic investigator and evidence from the machine
itself, network logs of proxies, central syslog, and IDS to paint a
good picture.  Recovering the evidence you deleted would be among the
things they'd have to do to determing the who/how.  

The most likely route of intrustion depends on what the server's
function was, how up to date on patches it was, and--if it was running
any web applications (particularly custom ones)--what vulnerabilities
in those applications would've have given an attacker an adequate
foothold to set up shop.

--
Todd Haverkos, LPT MsCompE
http://haverkos.com/

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL
certificate.  We look at how SSL works, how it benefits your company and how
your customers can tell if a site is secure. You will find out how to test,
purchase, install and use a thawte Digital Certificate on your Apache web
server. Throughout, best practices for set-up are highlighted to help you
ensure efficient ongoing management of your encryption keys and digital
certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727
d1
------------------------------------------------------------------------



------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how 
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Current thread: