Na 5 jaar toch maar eens een nieuwe sig :X | Roze nerdjes; ze bestaan ;P | All we need is one world wide vision - Queen | Novell servers reboot je om 11 uur, logisch toch? |:(
Na 5 jaar toch maar eens een nieuwe sig :X | Roze nerdjes; ze bestaan ;P | All we need is one world wide vision - Queen | Novell servers reboot je om 11 uur, logisch toch? |:(
Doubt thou the stars are fire; Doubt that the sun doth move; Doubt truth to be a liar; But never doubt I love.
file verwijderenOp vrijdag 31 mei 2002 16:26 schreef acq het volgende:
^ Niemand bekend mee?
rm -rf <filenaam>
echter op eigen risico
Verwijderd
Chrootkit: bedankt, ga ik mee bezig. Ik vat er echter nog steeds niets van. Kwam erachter dat die zip al 5 maand oud is ofzo
Na 5 jaar toch maar eens een nieuwe sig :X | Roze nerdjes; ze bestaan ;P | All we need is one world wide vision - Queen | Novell servers reboot je om 11 uur, logisch toch? |:(
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
| acq-highlander:/home/marc/chkrootkit-0.35 # ./chkrootkit ROOTDIR is `/' Checking `amd'... not found Checking `basename'... not infected Checking `biff'... not found Checking `chfn'... not infected Checking `chsh'... not infected Checking `cron'... not infected Checking `date'... not infected Checking `du'... not infected Checking `dirname'... not infected Checking `echo'... not infected Checking `egrep'... not infected Checking `env'... not infected Checking `find'... not infected Checking `fingerd'... not infected Checking `gpm'... not infected Checking `grep'... not infected Checking `hdparm'... not infected Checking `su'... not infected Checking `ifconfig'... not infected Checking `inetd'... not infected Checking `inetdconf'... not infected Checking `identd'... not infected Checking `killall'... not infected Checking `ldsopreload'... not infected Checking `login'... not infected Checking `ls'... not infected Checking `lsof'... not infected Checking `mail'... not infected Checking `mingetty'... not infected Checking `netstat'... not infected Checking `named'... not infected Checking `passwd'... not infected Checking `pidof'... not infected Checking `pop2'... not found Checking `pop3'... not found Checking `ps'... not infected Checking `pstree'... not infected Checking `rpcinfo'... not infected Checking `rlogind'... not infected Checking `rshd'... not infected Checking `slogin'... not infected Checking `sendmail'... not infected Checking `sshd'... not infected Checking `syslogd'... not infected Checking `tar'... not infected Checking `tcpd'... not infected Checking `top'... not infected Checking `telnetd'... not infected Checking `timed'... not found Checking `traceroute'... not infected Checking `write'... not infected Checking `aliens'... no suspect files Searching for sniffer's logs, it may take a while... nothing found Searching for HiDrootkit's default dir... nothing found Searching for t0rn's default files and dirs... nothing found Searching for t0rn's v8 defaults... nothing found Searching for Lion Worm default files and dirs... nothing found Searching for RSHA's default files and dir... nothing found Searching for RH-Sharpe's default files... nothing found Searching for Ambient's rootkit (ark) default files and dirs... nothing found Searching for suspicious files and dirs, it may take a while... /usr/lib/perl5/5.6.1/i586-linux/.packlist /usr/lib/perl5/site_perl/5.6.1/i586-linux/auto/Storable/.packlist /usr/lib/perl5/site_perl/5.6.1/i586-linux/auto/Tk/.packlist /usr/lib/perl5/site_perl/5.6.1/i586-linux/auto/Tk/GBARR/.packlist /usr/lib/perl5/site_perl/5.6.1/i586-linux/auto/Locale/gettext/.packlist /usr/lib/perl5/site_perl/5.6.1/i586-linux/auto/Digest/MD5/.packlist /usr/lib/perl5/site_perl/5.6.1/i586-linux/auto/HTML/Parser/.packlist /usr/lib/perl5/site_perl/5.6.1/i586-linux/auto/MIME/Base64/.packlist /usr/lib/perl5/site_perl/5.6.1/i586-linux/auto/U RI/.packlist /usr/lib/perl5/site_perl/5.6.1/i586-linux/auto/Net/.packlist /usr/lib/perl5/site_perl/5.6.1/i586-linux/auto/libwww-perl/.packlist /usr/lib/perl5/site_perl/5.6.1/i586-linux/auto/Term/ReadLine/Gnu/.packlist /usr/lib/perl5/site_perl/5.6.1/i586-linux/auto/w3mir/.packlist /usr/lib/perl5/site_perl/5.6.1/i586-linux/auto/Weblint/.packlist /usr/lib/perl5/site_perl/5.6.1/i586-linux/auto/IO/Stty/.packlist /usr/lib/perl5/site_perl/5.6.1/i586-linux/auto/IO/Tty/.packlist /usr/lib/perl5/site_perl/5.6.1/i586-linux/auto/Expect/.packlist /usr/lib/perl5/site_perl/5.6.1/i586-linux/auto/Cyrus/IMAP/.packlist /usr/lib/perl5/site_perl/5.6.1/i586-linux/auto/Cyrus/SIEVE/acap/.packlist /usr/lib/perl5/site_perl/5.6.1/i586-linux/auto/Cyrus/SIEVE/managesieve/.packlist /usr/lib/perl5/site_perl/5.6.1/i586-linux/auto/DBI/.packlist /usr/lib/perl5/site_perl/5.6.1/i586-linux/auto/Data/ShowTable/.packlist /usr/lib/perl5/site_perl/5.6.1/i586-linux/auto/Msql-Mysql-modules/.packlist /usr/lib/perl5/site_perl/5.6.1/i586-linux/auto/SNMP/.packlist /usr/lib/jdk1.1.8/bin/.java_wrapper /usr/lib/jdk1.1.8/bin/i686/green_threads/.extract_args /usr/lib/jdk1.1.8/bin/i686/native_threads/.extract_args Searching for LPD Worm files and dirs... nothing found Searching for Ramen Worm files and dirs... nothing found Searching for Maniac files and dirs... nothing found Searching for RK17 files and dirs... nothing found Searching for Ducoci rootkit... nothing found Searching for Adore Worm... nothing found Searching for ShitC Worm... nothing found Searching for Omega Worm... nothing found Searching for Sadmind/IIS Worm... nothing found Searching for MonKit... nothing found Searching for anomalies in shell history files... nothing found Checking `asp'... not infected Checking `bindshell'... not infected Checking `lkm'... nothing detected Checking `rexedcs'... not found Checking `sniffer'... eth0 is not promisc eth1 is not promisc ppp0 is not promisc Checking `wted'... nothing deleted Checking `z2'... nothing deleted acq-highlander:/home/marc/chkrootkit-0.35 # acq-highlander:/home/marc/chkrootkit-0.35 # |
Wat ie er allemaal uit spuugt bij: "Searching for suspicious files and dirs, it may take a while...", wordt ik niet zo vrolijk van. Zijn die files geinfecteerd? Bij een vriend van me hebben we dit ook uitgevoerd en daar kwam ie ook met Perl aan.
Na 5 jaar toch maar eens een nieuwe sig :X | Roze nerdjes; ze bestaan ;P | All we need is one world wide vision - Queen | Novell servers reboot je om 11 uur, logisch toch? |:(
Kort fragmentje:Op vrijdag 31 mei 2002 20:27 schreef Felix het volgende:
hij zal dat wel reporten omdat er die .packlist files staan.... wat staat daar in ?
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
| /usr/bin/a2p type=file /usr/bin/c2ph type=file /usr/bin/dprofpp type=file /usr/bin/find2perl type=file /usr/bin/h2ph type=file /usr/bin/h2xs type=file /usr/bin/perl from=/usr/bin/perl5.6.1 type=link /usr/bin/perl5.6.1 type=file /usr/bin/perlbug type=file /usr/bin/perlcc type=file /usr/bin/perldoc type=file /usr/bin/pl2pm type=file /usr/bin/pod2html type=file /usr/bin/pod2latex type=file /usr/bin/pod2man type=file /usr/bin/pod2text type=file /usr/bin/pod2usage type=file |
Weinig bijzonders dus denk ik
Na 5 jaar toch maar eens een nieuwe sig :X | Roze nerdjes; ze bestaan ;P | All we need is one world wide vision - Queen | Novell servers reboot je om 11 uur, logisch toch? |:(
Verwijderd
Een eventuele hacker kan natuurlijk op vele andere manieren een backdoor inbouwen, ik neem aan dat je al gekeken hebt of er speciale deamons draaien en of er geen vage poorten open staan? Je wachtwoorden zijn natuurlijk niet aangepast en er zijn ook geen nieuwe users bijgekomen? Is dat ook niet het geval dan is de virusscanner gewoon fout, mcafee gaf ook altijd aan dat er virussen in de kernel .tar.gz zaten.. yeh right
Wat je zowiezo altijd moet doen (ook als je geen problemen hebt) is backups maken en securitypatches installen.
* Wachtwoorden niet aangepastOp vrijdag 31 mei 2002 23:57 schreef wkamphuis het volgende:
Als chkchrootkit geen errors geeft heeft je systeem dus geen rootkit geinstalled. De .packist files zijn trouwens normaal.
Een eventuele hacker kan natuurlijk op vele andere manieren een backdoor inbouwen, ik neem aan dat je al gekeken hebt of er speciale deamons draaien en of er geen vage poorten open staan? Je wachtwoorden zijn natuurlijk niet aangepast en er zijn ook geen nieuwe users bijgekomen? Is dat ook niet het geval dan is de virusscanner gewoon fout, mcafee gaf ook altijd aan dat er virussen in de kernel .tar.gz zaten.. yeh right
Wat je zowiezo altijd moet doen (ook als je geen problemen hebt) is backups maken en securitypatches installen.
* Geen nieuwe users bijgekomen
* Geen vage poorten los
* Geen speciale deamons
Moet dan haast een fout zijn van de virusscanner
Enige (in mijn ogen) vreemde processen zijn nscd, maar na wat zoekwerk bleken dat normale deamons
Bedankt!
Na 5 jaar toch maar eens een nieuwe sig :X | Roze nerdjes; ze bestaan ;P | All we need is one world wide vision - Queen | Novell servers reboot je om 11 uur, logisch toch? |:(
yeah right.
Ik denk dat je het af en toe niet al te serieus moet opvatten.
Taaaa taa taa taaaa taa taa ta taaataaaaa.