public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
* ext3 hacked filesystem (by debian exim4 exploit) available for analysis and bugreporting
@ 2011-07-25 12:08 Luke Kenneth Casson Leighton
  2011-07-25 13:45 ` Matthias Schniedermeyer
  0 siblings, 1 reply; 11+ messages in thread
From: Luke Kenneth Casson Leighton @ 2011-07-25 12:08 UTC (permalink / raw)
  To: linux-kernel

folks, hi,

i appreciate this was some time ago, but i encountered a quite serious
issue with an ext3 filesystem that had been hacked, and a rootkit
installed.  this was with a 2.6.26 kernel.  the issue encountered was
that the little fuckers directly modified the ext3 filesystem so that
some files they had created could *not* be deleted.  when i say "could
not be deleted" i mean "absolutely could not be deleted".  also, fsck
did *not* report any "problems".

and yes, please do give me credit for knowing that you should use a
different system (offline) to analyse the [damaged] filesystem :)  as
you can imagine, i was very very surprised to encounter this as an
issue.

first thing: has anyone else encountered this?

second thing: if answer "no" to above, would anyone who can prove
their credentials (public ssh key, public web site, notability blah
blah) like to analyse the 5gb filesystem?  i still have a copy (it's
an LVM2 partition on a Xen hosted server).

apart from anything, this really really should go into rkhunter /
chkrootkit, but it requires someone with expertise to actually analyse
what the bloody hell happened.  apart from anything, files which
cannot be deleted (and cannot be detected as "corrupted" by fsck.ext3)
is pretty damn serious.

l.

^ permalink raw reply	[flat|nested] 11+ messages in thread

end of thread, other threads:[~2011-07-30 13:15 UTC | newest]

Thread overview: 11+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-07-25 12:08 ext3 hacked filesystem (by debian exim4 exploit) available for analysis and bugreporting Luke Kenneth Casson Leighton
2011-07-25 13:45 ` Matthias Schniedermeyer
2011-07-25 21:08   ` Luke Kenneth Casson Leighton
2011-07-29 19:59     ` Pavel Machek
2011-07-29 21:31       ` Matthias Schniedermeyer
2011-07-29 22:51         ` Pádraig Brady
2011-07-30  2:47           ` Kyle Moffett
2011-07-30  9:14           ` Jim Meyering
2011-07-30 13:03             ` Luke Kenneth Casson Leighton
2011-07-30 13:15           ` Luke Kenneth Casson Leighton
2011-07-30 12:58       ` Luke Kenneth Casson Leighton

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox