1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

Hacked Rootkits!

Discussion in 'Security' started by Fahd, Nov 11, 2007.

  1. #1
    One of my servers have been compromised by rootkits. I need some help to clean the system.

    Here is the relevant log entries from chkrootkit...

    Thanks in advance for any help! :)
     
    Fahd, Nov 11, 2007 IP
  2. ray9

    ray9 Guest

    Messages:
    69
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #2
    Steven from Rack911. torn rk means your server was not very secure, they are easy to prevent afaik.
     
    ray9, Nov 11, 2007 IP
  3. Fahd

    Fahd Well-Known Member

    Messages:
    2,152
    Likes Received:
    44
    Best Answers:
    0
    Trophy Points:
    100
    #3
    The info is appreciated but any help in fixing the issue at hand would be more helpful! Although I do understand where you are coming from.
     
    Fahd, Nov 11, 2007 IP
  4. WiredTree Zac

    WiredTree Zac Peon

    Messages:
    34
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #4
    The best course of action is going to be to back up all of your data and reinstall the server and make sure it is completely up to date. Then restore all your data and change your passwords and hire someone to secure your server and keep it up to date.

    Even if you remove the rootkits it found, unless you are a security expert, it is going to be tough to find other backdoors that chkrootkit doesn't find, and the safest way to deal with it will be to reinstall and restore.
     
    WiredTree Zac, Nov 12, 2007 IP
  5. whatyaknow

    whatyaknow Peon

    Messages:
    256
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #5
    I concur with WiredTree's assesment
     
    whatyaknow, Nov 28, 2007 IP
  6. SEO Extreme

    SEO Extreme Peon

    Messages:
    264
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #6
    I also agree with you... the safest, easiest, and best way to do it is just restore it. Hopefully you have backups and all!
     
    SEO Extreme, Nov 29, 2007 IP
  7. InFloW

    InFloW Peon

    Messages:
    1,488
    Likes Received:
    39
    Best Answers:
    0
    Trophy Points:
    0
    #7
    Keep in mind about false positives with programs like that. It's always best to use at least two rootkit checks so chkrootkit and maybe rhkhunter
     
    InFloW, Nov 30, 2007 IP
  8. whatyaknow

    whatyaknow Peon

    Messages:
    256
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #8
    Also, if you do a restore and the system's integrity is restored I would recommend installing tripwire. It is an easy solution that monitors system files on a daily basis to make sure the md5 sums remain the same.
     
    whatyaknow, Dec 4, 2007 IP
  9. craigedmonds

    craigedmonds Notable Member

    Messages:
    703
    Likes Received:
    131
    Best Answers:
    0
    Trophy Points:
    235
    #9
    Contact the guys at www.serveprogress.com.

    They do some ad hoc security work for me when I am too busy to do stuff myself.
     
    craigedmonds, Dec 8, 2007 IP
  10. SSANZ

    SSANZ Peon

    Messages:
    861
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    0
    #10
    tripwire doesn't monitor daily, it monitors all the time....?

    e.g

    I get your root pass via brute, i change your binaries before tripwire reports. I clean & patch tripwire... A very clean hack without you knowing that your binaries got exchanged...

    That was only an example to see an issue - Tripwire needs to know the binaries md5 hash all the time. So it checks every few minutes, just like LSM, LFD/CFD.

    * Sorry had to bring it up, just a daily check of binaries bugs the hell out of me.
     
    SSANZ, Dec 9, 2007 IP
  11. RectangleMan

    RectangleMan Notable Member

    Messages:
    2,825
    Likes Received:
    132
    Best Answers:
    0
    Trophy Points:
    210
    #11
    You are owned. Your only option is a complete reinstall. I would remove that drive completely asap. Install a new drive and reinstall your OS and files from scratch. Then attach the old drive and see what you can recover. Do so manually. Do not overwrite system files.

    Whatever you do don't try to patch up that old drive...it's owned and until you do a complete format on it with zero level...you can't use it.
     
    RectangleMan, Dec 14, 2007 IP
  12. grk519

    grk519 Peon

    Messages:
    293
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #12
    Hire a professional company to do it or you will get nowhere, this will cost upwards of $50. Otherwise, reformat.
     
    grk519, Dec 27, 2007 IP
  13. craigedmonds

    craigedmonds Notable Member

    Messages:
    703
    Likes Received:
    131
    Best Answers:
    0
    Trophy Points:
    235
    #13
    craigedmonds, Dec 28, 2007 IP