Vorige week is mijn server gedeeltelijk gehackt. Gedeeltelijk omdat het lijkt alsof de hack halverwege mislukt is. Ik vroeg me af wat er nu precies gebeurd is, en hoopte dat hier iemand daar meer over zou kunnen vertellen? Ik heb de server inmiddels opnieuw geinstalleerd maar wil herhaling natuurlijk voorkomen :-)
Voor zover ik uit de logs kan halen hebben ze op een of andere manier het root-password kunnen veranderen (daardoor kwam ik er ook achter), vervolgens hebben ze Bind gestart en geprobeerd in te loggen met ssh. Daarna is er niets meer gebeurd zo te zien. (Bind is overigens niet geconfigureerd, maar stond er alleen op vanwege de programmatjes die erbij komen, zoals dig. .) IP-adres heb ik helaas niet kunnen achterhalen.
Hieronder stukjes uit de logs:
Secure:
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Jun 15 04:40:05 kitten chfn[18082]: changed user `root' information
Jun 15 04:40:05 kitten chsh[18085]: changed user `root' shell to `/bin/bash'
Jun 15 04:40:06 kitten su[18123]: + ??? root-root
Jun 15 04:40:10 kitten passwd[18171]: password for `root' changed by `root'
Jun 15 04:40:12 kitten tcpd[18217]: warning: can't get client address: Socket operation on non-socket
Jun 15 04:40:12 kitten tcpd[18217]: connect from unknown
Jun 15 04:40:12 kitten tcpd[18217]: warning: can't get client address: Socket operation on non-socket
Jun 15 04:40:12 kitten tcpd[18217]: connect from unknown
Jun 15 04:40:12 kitten tcpd[18217]: warning: can't get client address: Socket operation on non-socket
Jun 15 04:40:12 kitten tcpd[18217]: connect from unknown
Jun 15 04:40:12 kitten tcpd[18217]: warning: can't get client address: Socket operation on non-socket
Jun 15 04:40:12 kitten tcpd[18217]: connect from unknown
Jun 15 04:40:12 kitten tcpd[18217]: warning: can't get client address: Socket operation on non-socket
....... en dat gaat nog een uurtje of wat zo door
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Syslog:
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Jun 15 04:40:06 kitten inetd[18130]: time/tcp (2): bind: Address already in use
Jun 15 04:40:06 kitten inetd[18130]: smtp/tcp (2): bind: Address already in use
Jun 15 04:40:12 kitten sshd[18207]: error: Bind to port 22 on 0.0.0.0 failed: Address already in use.
Jun 15 04:40:12 kitten sshd[18207]: fatal: Cannot bind any address.
Jun 15 04:50:06 kitten inetd[18130]: smtp/tcp (2): bind: Address already in use
Jun 15 04:50:06 kitten inetd[18130]: time/tcp (2): bind: Address already in use
Jun 15 05:00:06 kitten inetd[18130]: smtp/tcp (2): bind: Address already in use
Jun 15 05:00:06 kitten inetd[18130]: time/tcp (2): bind: Address already in use
Jun 15 05:10:06 kitten inetd[18130]: smtp/tcp (2): bind: Address already in use
Jun 15 05:10:06 kitten inetd[18130]: time/tcp (2): bind: Address already in use
Jun 15 05:20:06 kitten inetd[18130]: smtp/tcp (2): bind: Address already in use
Jun 15 05:20:06 kitten inetd[18130]: time/tcp (2): bind: Address already in use
...... en dat gaat zo dan nog een tijdje door
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Messages:
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Jun 15 04:40:10 kitten named[18168]: starting BIND 9.2.2
Jun 15 04:40:10 kitten named[18168]: using 1 CPU
Jun 15 04:40:10 kitten named[18168]: loading configuration from '/etc/named.conf'
Jun 15 04:40:11 kitten named[18168]: no IPv6 interfaces found
Jun 15 04:40:11 kitten named[18168]: listening on IPv4 interface lo, 127.0.0.1#53
Jun 15 04:40:11 kitten named[18168]: listening on IPv4 interface eth0, 172.20.xxx.yyy#53
Jun 15 04:40:11 kitten named[18168]: listening on IPv4 interface eth1, 192.168.1.1#53
Jun 15 04:40:11 kitten named[18168]: listening on IPv4 interface ppp0, 145.94.xxx.yyy#53
Jun 15 04:40:11 kitten named[18168]: command channel listening on 127.0.0.1#953
Jun 15 04:40:11 kitten named[18168]: zone 0.0.127.in-addr.arpa/IN: loaded serial 1997022700
Jun 15 04:40:11 kitten named[18168]: zone localhost/IN: loaded serial 42
Jun 15 04:40:11 kitten named[18168]: running
Jun 15 04:44:30 kitten n 15 04:44:30 tcpd[18217]: warning: can't get client address: Socket operation on non-socket
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
(die 145.94.xxx.yyy heb ik zo veranderd, ik weet niet of 't op dit moment verstandig is mijn ip-adres hier te posten ;-)
Voor zover ik uit de logs kan halen hebben ze op een of andere manier het root-password kunnen veranderen (daardoor kwam ik er ook achter), vervolgens hebben ze Bind gestart en geprobeerd in te loggen met ssh. Daarna is er niets meer gebeurd zo te zien. (Bind is overigens niet geconfigureerd, maar stond er alleen op vanwege de programmatjes die erbij komen, zoals dig. .) IP-adres heb ik helaas niet kunnen achterhalen.
Hieronder stukjes uit de logs:
Secure:
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Jun 15 04:40:05 kitten chfn[18082]: changed user `root' information
Jun 15 04:40:05 kitten chsh[18085]: changed user `root' shell to `/bin/bash'
Jun 15 04:40:06 kitten su[18123]: + ??? root-root
Jun 15 04:40:10 kitten passwd[18171]: password for `root' changed by `root'
Jun 15 04:40:12 kitten tcpd[18217]: warning: can't get client address: Socket operation on non-socket
Jun 15 04:40:12 kitten tcpd[18217]: connect from unknown
Jun 15 04:40:12 kitten tcpd[18217]: warning: can't get client address: Socket operation on non-socket
Jun 15 04:40:12 kitten tcpd[18217]: connect from unknown
Jun 15 04:40:12 kitten tcpd[18217]: warning: can't get client address: Socket operation on non-socket
Jun 15 04:40:12 kitten tcpd[18217]: connect from unknown
Jun 15 04:40:12 kitten tcpd[18217]: warning: can't get client address: Socket operation on non-socket
Jun 15 04:40:12 kitten tcpd[18217]: connect from unknown
Jun 15 04:40:12 kitten tcpd[18217]: warning: can't get client address: Socket operation on non-socket
....... en dat gaat nog een uurtje of wat zo door
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Syslog:
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Jun 15 04:40:06 kitten inetd[18130]: time/tcp (2): bind: Address already in use
Jun 15 04:40:06 kitten inetd[18130]: smtp/tcp (2): bind: Address already in use
Jun 15 04:40:12 kitten sshd[18207]: error: Bind to port 22 on 0.0.0.0 failed: Address already in use.
Jun 15 04:40:12 kitten sshd[18207]: fatal: Cannot bind any address.
Jun 15 04:50:06 kitten inetd[18130]: smtp/tcp (2): bind: Address already in use
Jun 15 04:50:06 kitten inetd[18130]: time/tcp (2): bind: Address already in use
Jun 15 05:00:06 kitten inetd[18130]: smtp/tcp (2): bind: Address already in use
Jun 15 05:00:06 kitten inetd[18130]: time/tcp (2): bind: Address already in use
Jun 15 05:10:06 kitten inetd[18130]: smtp/tcp (2): bind: Address already in use
Jun 15 05:10:06 kitten inetd[18130]: time/tcp (2): bind: Address already in use
Jun 15 05:20:06 kitten inetd[18130]: smtp/tcp (2): bind: Address already in use
Jun 15 05:20:06 kitten inetd[18130]: time/tcp (2): bind: Address already in use
...... en dat gaat zo dan nog een tijdje door
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Messages:
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Jun 15 04:40:10 kitten named[18168]: starting BIND 9.2.2
Jun 15 04:40:10 kitten named[18168]: using 1 CPU
Jun 15 04:40:10 kitten named[18168]: loading configuration from '/etc/named.conf'
Jun 15 04:40:11 kitten named[18168]: no IPv6 interfaces found
Jun 15 04:40:11 kitten named[18168]: listening on IPv4 interface lo, 127.0.0.1#53
Jun 15 04:40:11 kitten named[18168]: listening on IPv4 interface eth0, 172.20.xxx.yyy#53
Jun 15 04:40:11 kitten named[18168]: listening on IPv4 interface eth1, 192.168.1.1#53
Jun 15 04:40:11 kitten named[18168]: listening on IPv4 interface ppp0, 145.94.xxx.yyy#53
Jun 15 04:40:11 kitten named[18168]: command channel listening on 127.0.0.1#953
Jun 15 04:40:11 kitten named[18168]: zone 0.0.127.in-addr.arpa/IN: loaded serial 1997022700
Jun 15 04:40:11 kitten named[18168]: zone localhost/IN: loaded serial 42
Jun 15 04:40:11 kitten named[18168]: running
Jun 15 04:44:30 kitten n 15 04:44:30 tcpd[18217]: warning: can't get client address: Socket operation on non-socket
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
(die 145.94.xxx.yyy heb ik zo veranderd, ik weet niet of 't op dit moment verstandig is mijn ip-adres hier te posten ;-)
[ Voor 3% gewijzigd door Verwijderd op 21-06-2004 00:39 ]