From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Keith R. Weiner" Subject: RE: some body hacked my system Date: Tue, 8 Oct 2002 11:17:34 -0400 Sender: netfilter-admin@lists.netfilter.org Message-ID: Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="----_=_NextPart_001_01C26EDD.D43D4878" Return-path: content-class: urn:content-classes:message Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: Sundaram Ramasamy , netfilter@lists.netfilter.org This is a multi-part message in MIME format. ------_=_NextPart_001_01C26EDD.D43D4878 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable That looks like warcraft 3 if I had to take a guess. It is a very good = game. Did you try unarchiving it? =20 You can block his ip address, but what is stopping this person from = hitting you from another ip? =20 Look at your ftp server. Maybe disable anonymous logins. Maybe put = quotas on. Maybe see if there are any patches to your ftp daemon. =20 What kind of ftp server are you using? WuFTPD, ms IIS, etc...? =20 I'm a newbie myself, but I'd just thought that I'd put in my 2 cents. -----Original Message----- From: Sundaram Ramasamy [mailto:sun@percipia.com] Sent: Tuesday, October 08, 2002 11:08 AM To: netfilter@lists.netfilter.org Subject: some body hacked my system Hi, I am allowing ftp connection in my firewall, some body used ftp port, = filled my hard disk space. He logged-in from 68.65.58.159 IP (/var/log/message) Oct 8 00:57:03 linux2 ftpd[25101]: FTP LOGIN FROM va-staff-u1-c5a-159.frbgva.adelphia.net [68.65.58.159] he created directory named WC3 and transfed follwoing files. bash-2.04# cd WC3 bash-2.04# ls wc3.part01.rar.gz wc3.part07.rar.gz wc3.part13.rar.gz = wc3.part19.rar.gz wc3.part02.rar.gz wc3.part08.rar.gz wc3.part14.rar.gz = wc3.part20.rar.gz wc3.part03.rar.gz wc3.part09.rar.gz wc3.part15.rar.gz = wc3.part21.rar.gz wc3.part04.rar.gz wc3.part10.rar.gz wc3.part16.rar.gz wc3.part05.rar.gz wc3.part11.rar.gz wc3.part17.rar.gz wc3.part06.rar.gz wc3.part12.rar.gz wc3.part18.rar.gz Is anybody knows what this file used for? How will i block this IP Address in my firewall? How will i check what else he did on my machine? Thanks SR ------_=_NextPart_001_01C26EDD.D43D4878 Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable
That=20 looks like warcraft 3 if I had to take a guess.  It is a very good = game.=20 Did you try unarchiving it?
 
You=20 can block his ip address, but what is stopping this person from hitting = you from=20 another ip?
 
Look=20 at your ftp server.  Maybe disable anonymous logins. Maybe put quotas on.  Maybe see = if there=20 are any patches to your ftp daemon.
 
What=20 kind of ftp server are you using?  WuFTPD, ms IIS,=20 etc...?
 
I'm a newbie myself, but I'd just = thought that=20 I'd put in my 2 cents.
-----Original Message-----
From: Sundaram Ramasamy=20 [mailto:sun@percipia.com]
Sent: Tuesday, October 08, 2002 = 11:08=20 AM
To: netfilter@lists.netfilter.org
Subject: some = body=20 hacked my system

Hi,

I=20 am allowing ftp connection in my firewall, some body used ftp port,=20 filled
my hard disk space. He logged-in from 68.65.58.159 IP=20 (/var/log/message)

Oct  8 00:57:03 linux2 ftpd[25101]: FTP = LOGIN=20 FROM
va-staff-u1-c5a-159.frbgva.adelphia.net = [68.65.58.159]

he=20 created directory named WC3 and transfed follwoing = files.

bash-2.04# cd=20 WC3
bash-2.04# ls
wc3.part01.rar.gz  = wc3.part07.rar.gz =20 wc3.part13.rar.gz  wc3.part19.rar.gz
wc3.part02.rar.gz =20 wc3.part08.rar.gz  wc3.part14.rar.gz =20 wc3.part20.rar.gz
wc3.part03.rar.gz  wc3.part09.rar.gz =20 wc3.part15.rar.gz  wc3.part21.rar.gz
wc3.part04.rar.gz =20 wc3.part10.rar.gz  wc3.part16.rar.gz
wc3.part05.rar.gz =20 wc3.part11.rar.gz  wc3.part17.rar.gz
wc3.part06.rar.gz =20 wc3.part12.rar.gz  wc3.part18.rar.gz

Is anybody knows what = this=20 file used for?

How will i block this IP Address in my=20 firewall?

How will i check what else he did on my=20 = machine?

Thanks
SR

<= /HTML> ------_=_NextPart_001_01C26EDD.D43D4878-- From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Sundaram Ramasamy" Subject: some body hacked my system Date: Tue, 8 Oct 2002 11:07:37 -0400 Sender: netfilter-admin@lists.netfilter.org Message-ID: <001e01c26edc$73aca530$8c01a8c0@sundaram> Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_001B_01C26EBA.E9541790" Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: netfilter@lists.netfilter.org This is a multi-part message in MIME format. ------=_NextPart_000_001B_01C26EBA.E9541790 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Hi, I am allowing ftp connection in my firewall, some body used ftp port, = filled my hard disk space. He logged-in from 68.65.58.159 IP (/var/log/message) Oct 8 00:57:03 linux2 ftpd[25101]: FTP LOGIN FROM va-staff-u1-c5a-159.frbgva.adelphia.net [68.65.58.159] he created directory named WC3 and transfed follwoing files. bash-2.04# cd WC3 bash-2.04# ls wc3.part01.rar.gz wc3.part07.rar.gz wc3.part13.rar.gz = wc3.part19.rar.gz wc3.part02.rar.gz wc3.part08.rar.gz wc3.part14.rar.gz = wc3.part20.rar.gz wc3.part03.rar.gz wc3.part09.rar.gz wc3.part15.rar.gz = wc3.part21.rar.gz wc3.part04.rar.gz wc3.part10.rar.gz wc3.part16.rar.gz wc3.part05.rar.gz wc3.part11.rar.gz wc3.part17.rar.gz wc3.part06.rar.gz wc3.part12.rar.gz wc3.part18.rar.gz Is anybody knows what this file used for? How will i block this IP Address in my firewall? How will i check what else he did on my machine? Thanks SR ------=_NextPart_000_001B_01C26EBA.E9541790 Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable
Hi,

I am=20 allowing ftp connection in my firewall, some body used ftp port, = filled
my=20 hard disk space. He logged-in from 68.65.58.159 IP=20 (/var/log/message)

Oct  8 00:57:03 linux2 ftpd[25101]: FTP = LOGIN=20 FROM
va-staff-u1-c5a-159.frbgva.adelphia.net [68.65.58.159]

he = created=20 directory named WC3 and transfed follwoing files.

bash-2.04# cd=20 WC3
bash-2.04# ls
wc3.part01.rar.gz  wc3.part07.rar.gz =20 wc3.part13.rar.gz  wc3.part19.rar.gz
wc3.part02.rar.gz =20 wc3.part08.rar.gz  wc3.part14.rar.gz =20 wc3.part20.rar.gz
wc3.part03.rar.gz  wc3.part09.rar.gz =20 wc3.part15.rar.gz  wc3.part21.rar.gz
wc3.part04.rar.gz =20 wc3.part10.rar.gz  wc3.part16.rar.gz
wc3.part05.rar.gz =20 wc3.part11.rar.gz  wc3.part17.rar.gz
wc3.part06.rar.gz =20 wc3.part12.rar.gz  wc3.part18.rar.gz

Is anybody knows what = this file=20 used for?

How will i block this IP Address in my = firewall?

How=20 will i check what else he did on my=20 machine?

Thanks
SR

------=_NextPart_000_001B_01C26EBA.E9541790-- From mboxrd@z Thu Jan 1 00:00:00 1970 From: Carlos E Gorges Subject: Re: some body hacked my system Date: Tue, 8 Oct 2002 12:41:13 -0300 Sender: netfilter-admin@lists.netfilter.org Message-ID: <200210081241.13436.carlos@techlinux.com.br> References: <001e01c26edc$73aca530$8c01a8c0@sundaram> Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable Return-path: In-Reply-To: <001e01c26edc$73aca530$8c01a8c0@sundaram> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="iso-8859-1" To: Sundaram Ramasamy , netfilter@lists.netfilter.org On Ter=E7a 08 Outubro 2002 12:07, Sundaram Ramasamy wrote: > Hi, > > I am allowing ftp connection in my firewall, some body used ftp port, > filled my hard disk space. He logged-in from 68.65.58.159 IP > (/var/log/message) > > Oct 8 00:57:03 linux2 ftpd[25101]: FTP LOGIN FROM > va-staff-u1-c5a-159.frbgva.adelphia.net [68.65.58.159] > > he created directory named WC3 and transfed follwoing files. > > bash-2.04# cd WC3 > bash-2.04# ls > wc3.part01.rar.gz wc3.part07.rar.gz wc3.part13.rar.gz wc3.part19.rar= .gz > wc3.part02.rar.gz wc3.part08.rar.gz wc3.part14.rar.gz wc3.part20.rar= .gz > wc3.part03.rar.gz wc3.part09.rar.gz wc3.part15.rar.gz wc3.part21.rar= .gz > wc3.part04.rar.gz wc3.part10.rar.gz wc3.part16.rar.gz > wc3.part05.rar.gz wc3.part11.rar.gz wc3.part17.rar.gz > wc3.part06.rar.gz wc3.part12.rar.gz wc3.part18.rar.gz Wacraft 3 warez ? --=20 _________________________ Carlos E Gorges =20 (carlos@techlinux.com.br) Tech inform=E1tica LTDA Brazil =20 _________________________ From mboxrd@z Thu Jan 1 00:00:00 1970 From: Dominic Irrcher Subject: RE: some body hacked my system Date: Tue, 8 Oct 2002 13:17:40 -0400 Sender: netfilter-admin@lists.netfilter.org Message-ID: Mime-Version: 1.0 Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit To: 'Carlos E Gorges' , 'Sundaram Ramasamy' , "'netfilter@lists.netfilter.org'" yes ... those do look like warcraft3 warez files !!! if you want to block just his ip .. drop any incoming connections with the source ip of what you posted. keep checking your log files, might not tell you everything he did, but its a good indication. consider shutting off ftp .. and running sftp instead. or a better ftp package. HTH From mboxrd@z Thu Jan 1 00:00:00 1970 From: Maciej Soltysiak Subject: Re: some body hacked my system Date: Tue, 8 Oct 2002 22:01:59 +0200 (CEST) Sender: netfilter-admin@lists.netfilter.org Message-ID: References: <001e01c26edc$73aca530$8c01a8c0@sundaram> Mime-Version: 1.0 Return-path: In-Reply-To: <001e01c26edc$73aca530$8c01a8c0@sundaram> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: TEXT/PLAIN; charset="us-ascii" Content-Transfer-Encoding: 7bit To: Sundaram Ramasamy Cc: netfilter@lists.netfilter.org > wc3.part01.rar.gz wc3.part07.rar.gz wc3.part13.rar.gz wc3.part19.rar.gz > wc3.part02.rar.gz wc3.part08.rar.gz wc3.part14.rar.gz wc3.part20.rar.gz > wc3.part03.rar.gz wc3.part09.rar.gz wc3.part15.rar.gz wc3.part21.rar.gz > wc3.part04.rar.gz wc3.part10.rar.gz wc3.part16.rar.gz > wc3.part05.rar.gz wc3.part11.rar.gz wc3.part17.rar.gz > wc3.part06.rar.gz wc3.part12.rar.gz wc3.part18.rar.gz > > Is anybody knows what this file used for? Of course. The famous, War Craft III. > How will i block this IP Address in my firewall? iptables -A INPUT -s -j DROP > How will i check what else he did on my machine? Well, maybe i did not get it right, be it looks as if someone is making a Warez site out of your machine. The easiest way evil people exploit it is that they use world writeable anonymous ftp servers. Check it. If it is an intrusion, go and browse the logs, look in .bash.history, suspicious users, processes, mc's history, again: logs. look for deleted parts in the logs. And download, compile and run: chkrootkit. Which looks for rootkits and trojans in you binaries. Good luck, Maciej Soltysiak From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Sundaram Ramasamy" Subject: Re: some body hacked my system Date: Tue, 8 Oct 2002 17:53:04 -0400 Sender: netfilter-admin@lists.netfilter.org Message-ID: <002f01c26f15$16c571b0$8c01a8c0@sundaram> References: Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: netfilter@lists.netfilter.org Thanks for all your mails, other than filling my hard disk he didn't do anything. I am running Redhat 7.1 wu-ftpd, in my firewall I opened only http, smtp, pop3, ftp and cvspserver ports. Thanks Sundaram ----- Original Message ----- From: "Kevin Dwyer" To: "Sundaram Ramasamy" Cc: Sent: Tuesday, October 08, 2002 5:12 PM Subject: Re: some body hacked my system > On Tue, 8 Oct 2002, Maciej Soltysiak transmitted the following: > > > And download, compile and run: chkrootkit. Which looks for rootkits and > > trojans in you binaries. > > And check the checksums of your binaries with the ones you saved off on > disk when you finished building the machine. ;) > > > /* Kevin Dwyer Allegiance Internet */ > /* network security engineer Commerce Center II */ > /* email: Kevin.Dwyer@algx.net 7601 Ora Glen Drive */ > /* phone: 240-616-2075 Greenbelt, MD 20770 */ > /* >++++++++++[<++++++++++>-]<.+++++.----.[-]++++++++++. */ > > > From mboxrd@z Thu Jan 1 00:00:00 1970 From: Kevin Dwyer Subject: Re: some body hacked my system Date: Tue, 8 Oct 2002 17:12:35 -0400 (EDT) Sender: netfilter-admin@lists.netfilter.org Message-ID: References: Mime-Version: 1.0 Return-path: In-Reply-To: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: TEXT/PLAIN; charset="us-ascii" Content-Transfer-Encoding: 7bit To: Sundaram Ramasamy Cc: netfilter@lists.netfilter.org On Tue, 8 Oct 2002, Maciej Soltysiak transmitted the following: > And download, compile and run: chkrootkit. Which looks for rootkits and > trojans in you binaries. And check the checksums of your binaries with the ones you saved off on disk when you finished building the machine. ;) /* Kevin Dwyer Allegiance Internet */ /* network security engineer Commerce Center II */ /* email: Kevin.Dwyer@algx.net 7601 Ora Glen Drive */ /* phone: 240-616-2075 Greenbelt, MD 20770 */ /* >++++++++++[<++++++++++>-]<.+++++.----.[-]++++++++++. */ From mboxrd@z Thu Jan 1 00:00:00 1970 From: Bob Sully Subject: RE: some body hacked my system Date: Tue, 8 Oct 2002 15:07:31 -0700 (PDT) Sender: netfilter-admin@lists.netfilter.org Message-ID: References: Mime-Version: 1.0 Return-path: In-Reply-To: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: TEXT/PLAIN; charset="us-ascii" Content-Transfer-Encoding: 7bit To: "Keith R. Weiner" Cc: Sundaram Ramasamy , netfilter@lists.netfilter.org I use ProFTPd. If you need anonymous access, set it up with upload-only privileges (no read or download) on /incoming and do not allow the creation of directories. Set up your other directories as download-only. I have never had a problem with this setup. HTH -- Bob On Tue, 8 Oct 2002, Keith R. Weiner wrote: > That looks like warcraft 3 if I had to take a guess. It is a very good game. Did you try unarchiving it? > > You can block his ip address, but what is stopping this person from hitting you from another ip? > > Look at your ftp server. Maybe disable anonymous logins. Maybe put quotas on. Maybe see if there are any patches to your ftp daemon. > > What kind of ftp server are you using? WuFTPD, ms IIS, etc...? > > I'm a newbie myself, but I'd just thought that I'd put in my 2 cents. > > -----Original Message----- > From: Sundaram Ramasamy [mailto:sun@percipia.com] > Sent: Tuesday, October 08, 2002 11:08 AM > To: netfilter@lists.netfilter.org > Subject: some body hacked my system > > > Hi, > > I am allowing ftp connection in my firewall, some body used ftp port, filled > my hard disk space. He logged-in from 68.65.58.159 IP (/var/log/message) > > Oct 8 00:57:03 linux2 ftpd[25101]: FTP LOGIN FROM > va-staff-u1-c5a-159.frbgva.adelphia.net [68.65.58.159] > > he created directory named WC3 and transfed follwoing files. > > bash-2.04# cd WC3 > bash-2.04# ls > wc3.part01.rar.gz wc3.part07.rar.gz wc3.part13.rar.gz wc3.part19.rar.gz > wc3.part02.rar.gz wc3.part08.rar.gz wc3.part14.rar.gz wc3.part20.rar.gz > wc3.part03.rar.gz wc3.part09.rar.gz wc3.part15.rar.gz wc3.part21.rar.gz > wc3.part04.rar.gz wc3.part10.rar.gz wc3.part16.rar.gz > wc3.part05.rar.gz wc3.part11.rar.gz wc3.part17.rar.gz > wc3.part06.rar.gz wc3.part12.rar.gz wc3.part18.rar.gz > > Is anybody knows what this file used for? > > How will i block this IP Address in my firewall? > > How will i check what else he did on my machine? > > Thanks > SR > > > -- ________________________________________ Bob Sully - Simi Valley, California, USA http://www.malibyte.net "The weather is here - wish you were beautiful." - J. Buffett From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Michael H. Warfield" Subject: Re: some body hacked my system Date: Tue, 8 Oct 2002 14:36:22 -0400 Sender: netfilter-admin@lists.netfilter.org Message-ID: <20021008183622.GA26919@alcove.wittsend.com> References: <001e01c26edc$73aca530$8c01a8c0@sundaram> Mime-Version: 1.0 Return-path: Content-Disposition: inline In-Reply-To: <001e01c26edc$73aca530$8c01a8c0@sundaram> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit To: Sundaram Ramasamy Cc: netfilter@lists.netfilter.org On Tue, Oct 08, 2002 at 11:07:37AM -0400, Sundaram Ramasamy wrote: > Hi, > I am allowing ftp connection in my firewall, some body used ftp port, filled > my hard disk space. He logged-in from 68.65.58.159 IP (/var/log/message) > Oct 8 00:57:03 linux2 ftpd[25101]: FTP LOGIN FROM > va-staff-u1-c5a-159.frbgva.adelphia.net [68.65.58.159] > he created directory named WC3 and transfed follwoing files. > bash-2.04# cd WC3 > bash-2.04# ls > wc3.part01.rar.gz wc3.part07.rar.gz wc3.part13.rar.gz wc3.part19.rar.gz > wc3.part02.rar.gz wc3.part08.rar.gz wc3.part14.rar.gz wc3.part20.rar.gz > wc3.part03.rar.gz wc3.part09.rar.gz wc3.part15.rar.gz wc3.part21.rar.gz > wc3.part04.rar.gz wc3.part10.rar.gz wc3.part16.rar.gz > wc3.part05.rar.gz wc3.part11.rar.gz wc3.part17.rar.gz > wc3.part06.rar.gz wc3.part12.rar.gz wc3.part18.rar.gz > Is anybody knows what this file used for? > How will i block this IP Address in my firewall? > How will i check what else he did on my machine? 1) He did not "hack" your box. You invited him in by leaving anonymous ftp enabled. He's just using you as a warez drop site. I guess he could have told you "thanks". 2) Never never NEVER allow both read and write access to any directories under ftp home directory. You are useless as a warez site if his buddies can't download what he uploaded. If you want people to be able to upload stuff, have a writable upload directory that can not be read. Then move the stuff you want to be available for download to a readable directory. 3) Blocking his IP isn't going to do diddley worth of good once he tells his 10,000 buddies on IRC that he just found a fat disk with an IP address. 4) If you want to check your system for tampering, run an rpm verify run to check the installed system. 5) If you think he really did hack your system, run ckrootkit, on it (read the instructions - it's very noisy and has some false alarms - don't panic if it complains about hidden processes, just rerun it and verify). 6) If you think he's REALLY GOOD (and he's not if he's just flicking his bic playing with warez) then reinstall. You won't find the good ones unless you have offline databases of your installed base and verify using a bootable CD and verifiable software. > Thanks > SR Mike -- Michael H. Warfield | (770) 985-6132 | mhw@WittsEnd.com /\/\|=mhw=|\/\/ | (678) 463-0932 | http://www.wittsend.com/mhw/ NIC whois: MHW9 | An optimist believes we live in the best of all PGP Key: 0xDF1DD471 | possible worlds. A pessimist is sure of it! From mboxrd@z Thu Jan 1 00:00:00 1970 From: Vito Louis Sansevero Subject: Re: some body hacked my system Date: 08 Oct 2002 08:24:29 -0700 Sender: netfilter-admin@lists.netfilter.org Message-ID: <1034090673.23877.0.camel@gentoo.vito> References: <001e01c26edc$73aca530$8c01a8c0@sundaram> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <001e01c26edc$73aca530$8c01a8c0@sundaram> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: Sundaram Ramasamy Cc: netfilter@lists.netfilter.org Well it looks like to me that you gave FTP access to a friend, and he is uploading the Warez version of "War Craft 3" in rar.gz format, Hey dont look a gift horse in the mouth! :) On Tue, 2002-10-08 at 08:07, Sundaram Ramasamy wrote: > Hi, > > I am allowing ftp connection in my firewall, some body used ftp port, > filled > my hard disk space. He logged-in from 68.65.58.159 IP (/var/log/message) > > Oct 8 00:57:03 linux2 ftpd[25101]: FTP LOGIN FROM > va-staff-u1-c5a-159.frbgva.adelphia.net [68.65.58.159] > > he created directory named WC3 and transfed follwoing files. > > bash-2.04# cd WC3 > bash-2.04# ls > wc3.part01.rar.gz wc3.part07.rar.gz wc3.part13.rar.gz > wc3.part19.rar.gz > wc3.part02.rar.gz wc3.part08.rar.gz wc3.part14.rar.gz > wc3.part20.rar.gz > wc3.part03.rar.gz wc3.part09.rar.gz wc3.part15.rar.gz > wc3.part21.rar.gz > wc3.part04.rar.gz wc3.part10.rar.gz wc3.part16.rar.gz > wc3.part05.rar.gz wc3.part11.rar.gz wc3.part17.rar.gz > wc3.part06.rar.gz wc3.part12.rar.gz wc3.part18.rar.gz > > Is anybody knows what this file used for? > > How will i block this IP Address in my firewall? > > How will i check what else he did on my machine? > > Thanks > SR > -- Vito Sansevero Unix Network Admin The Linksys Group From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Michael H. Warfield" Subject: Re: some body hacked my system Date: Wed, 9 Oct 2002 14:26:05 -0400 Sender: netfilter-admin@lists.netfilter.org Message-ID: <20021009182605.GA2974@alcove.wittsend.com> References: <002f01c26f15$16c571b0$8c01a8c0@sundaram> Mime-Version: 1.0 Return-path: Content-Disposition: inline In-Reply-To: <002f01c26f15$16c571b0$8c01a8c0@sundaram> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit To: Sundaram Ramasamy Cc: netfilter@lists.netfilter.org On Tue, Oct 08, 2002 at 05:53:04PM -0400, Sundaram Ramasamy wrote: > Thanks for all your mails, other than filling my hard disk he didn't do > anything. I am running Redhat 7.1 wu-ftpd, in my firewall I opened only > http, smtp, pop3, ftp and cvspserver ports. Hmmm... Really... RedHat 7.1 huh... What was that IP address again. /;->=> Have you kept that very VERY up to date? 7.1 was one of those spins with security problems from hell. Just the i386 binary rpm updates for 7.1 are almost 380 Meg worth. The entire update directory for 7.1 (including sources and other platforms) is over a Gig and a half. ftp - Yup... There's an update rpm in there for that. smtp - Uh huh... Sendmail too. http - You betcha... Apache problems fixed in there too. pop3 - That's in the imap package and that's got an update. You're at least 4 for 5 in the security hole department unless you've updated those four to the latest rpms. On top of those, since you are running http, you can add problems in php and possibly others than apache can access. You didn't mention https, but that's got openssl problems that could get you "slapped" (slapper Apache OpenSSL worm running loose right now). Your earlier message didn't indicate a breakin. But this one indicates a potential for future breakins. If you are not going to upgrade that to a more recent distro, you are going to need to be doubly sure to keep it up to date. Running up2date and joining RedHat networks (rhn) would probably be a good idea if you haven't already. :-) > Thanks > Sundaram > ----- Original Message ----- > From: "Kevin Dwyer" > To: "Sundaram Ramasamy" > Cc: > Sent: Tuesday, October 08, 2002 5:12 PM > Subject: Re: some body hacked my system > > > > On Tue, 8 Oct 2002, Maciej Soltysiak transmitted the following: > > > > > And download, compile and run: chkrootkit. Which looks for rootkits and > > > trojans in you binaries. > > > > And check the checksums of your binaries with the ones you saved off on > > disk when you finished building the machine. ;) > > > > > > /* Kevin Dwyer Allegiance Internet */ > > /* network security engineer Commerce Center II */ > > /* email: Kevin.Dwyer@algx.net 7601 Ora Glen Drive */ > > /* phone: 240-616-2075 Greenbelt, MD 20770 */ > > /* >++++++++++[<++++++++++>-]<.+++++.----.[-]++++++++++. */ > > > > > > > -- Michael H. Warfield | (770) 985-6132 | mhw@WittsEnd.com /\/\|=mhw=|\/\/ | (678) 463-0932 | http://www.wittsend.com/mhw/ NIC whois: MHW9 | An optimist believes we live in the best of all PGP Key: 0xDF1DD471 | possible worlds. A pessimist is sure of it!