Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Security and Privacy
FedoraForum Search

Forgot Password? Join Us!

Security and Privacy Sadly, malware, spyware, hackers and privacy threats abound in today's world. Let's be paranoid and secure our penguins, and slam the doors on privacy exploits.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 25th January 2007, 12:26 PM
paul matthijsse Offline
Registered User
 
Join Date: Sep 2005
Location: Dieulefit, France
Posts: 721
System out of control - hacked I guess...? (solved)

Hello,

Little problem here, I have no longer control over my machine (FC 6). This happened after clicking on a bittorrent link (yep, somewhere deep down in the underground area...). What happens is that modprobe is running and takes up all the cpu. Can't kill that process anymore (tried that as su as well of course).

Rkhunter and chkrootkit do not find suspect things (except that rkhunter gives a lot of BAD messages in the beginning, but I saw that before. Has to do with out of date hashes or something). Firewall is on, no trusted ports selected, I added this morning 6881 udp/tcp as extra ports for the bittorrent client, don't see them anymore now... SELinux is off.

Attached are screendumps of top, rkhunter and chkrootkit. What's that MD5 problem in the rkhunter dump?

Any ideas what to do?

TIA, Paul.

PS. For the moment I did not reboot, because I am not sure that's the solution (and my uptime is 18 days, want to keep that! :-)
Attached Thumbnails
Click image for larger version

Name:	modprobe.png
Views:	83
Size:	78.1 KB
ID:	11228   Click image for larger version

Name:	chkrootkit.png
Views:	73
Size:	70.9 KB
ID:	11229   Click image for larger version

Name:	rkhunter_results.png
Views:	83
Size:	41.5 KB
ID:	11230  

Last edited by paul matthijsse; 25th January 2007 at 01:06 PM.
Reply With Quote
  #2  
Old 25th January 2007, 12:30 PM
leigh123linux's Avatar
leigh123linux Offline
Retired Administrator
 
Join Date: Oct 2006
Posts: 21,509
reboot____________
__________________
My Hardware
- CPU: AMD Phenom II X6 Hex Core 1055T 95W Edition @3.5Ghz
- Motherboard: Gigabyte GA-880GM-UD2H
- Cooler: Corsair H50 CPU Cooler
- RAM: Corsair Dominator 8GB (4x2GB) DDR3 1600MHz
- Graphics: Gigabyte GeForce GTS 450 OC 1024MB GDDR5
Reply With Quote
  #3  
Old 25th January 2007, 01:04 PM
paul matthijsse Offline
Registered User
 
Join Date: Sep 2005
Location: Dieulefit, France
Posts: 721
I had to reboot indeed, because suspend didn't work as usual. Monitor went down but the machine stayed up, including the jamming cpu fan. Now the problem is over. I looked in the sys logs but couldn't find anything releated.

Question remains what this was...

Thanks for answering.

Cheers, Paul.

PS. My uptime is now 0d0h22m :-)
Reply With Quote
  #4  
Old 25th January 2007, 01:15 PM
leigh123linux's Avatar
leigh123linux Offline
Retired Administrator
 
Join Date: Oct 2006
Posts: 21,509
I dont think you have been hacked.

Did you start modprobe
__________________
My Hardware
- CPU: AMD Phenom II X6 Hex Core 1055T 95W Edition @3.5Ghz
- Motherboard: Gigabyte GA-880GM-UD2H
- Cooler: Corsair H50 CPU Cooler
- RAM: Corsair Dominator 8GB (4x2GB) DDR3 1600MHz
- Graphics: Gigabyte GeForce GTS 450 OC 1024MB GDDR5
Reply With Quote
  #5  
Old 25th January 2007, 01:34 PM
paul matthijsse Offline
Registered User
 
Join Date: Sep 2005
Location: Dieulefit, France
Posts: 721
No, I didn start modprobe myself. I saw immediately after the download began, that my cpu went to 100% and top said it was modprobe doing that. As said, I was unable to kill it. man modprobe told me that it is a program to add and remove modules from the Linux kernel. Was someone trying to remove some security or logging stuff from the kernel?
Reply With Quote
  #6  
Old 25th January 2007, 01:44 PM
leigh123linux's Avatar
leigh123linux Offline
Retired Administrator
 
Join Date: Oct 2006
Posts: 21,509
Quote:
Originally Posted by paul matthijsse
No, I didn start modprobe myself. I saw immediately after the download began, that my cpu went to 100% and top said it was modprobe doing that. As said, I was unable to kill it. man modprobe told me that it is a program to add and remove modules from the Linux kernel. Was someone trying to remove some security or logging stuff from the kernel?

It's more likely a error in FC6 , did you update in the 18 days uptime
__________________
My Hardware
- CPU: AMD Phenom II X6 Hex Core 1055T 95W Edition @3.5Ghz
- Motherboard: Gigabyte GA-880GM-UD2H
- Cooler: Corsair H50 CPU Cooler
- RAM: Corsair Dominator 8GB (4x2GB) DDR3 1600MHz
- Graphics: Gigabyte GeForce GTS 450 OC 1024MB GDDR5
Reply With Quote
  #7  
Old 25th January 2007, 01:52 PM
paul matthijsse Offline
Registered User
 
Join Date: Sep 2005
Location: Dieulefit, France
Posts: 721
yes I did upgrade some things. Since 4 january:
* cairo
* gtk2
* gtk2-devel
* hddtemp
* evolution
* cpuspeed
* gimp-print
* lm_sensors
* gettext

Not really modprobe related isn't it?
Reply With Quote
  #8  
Old 25th January 2007, 01:58 PM
leigh123linux's Avatar
leigh123linux Offline
Retired Administrator
 
Join Date: Oct 2006
Posts: 21,509
I am not sure but cpuspeed can load modules

http://carlthompson.net/Software/CPUSpeed
__________________
My Hardware
- CPU: AMD Phenom II X6 Hex Core 1055T 95W Edition @3.5Ghz
- Motherboard: Gigabyte GA-880GM-UD2H
- Cooler: Corsair H50 CPU Cooler
- RAM: Corsair Dominator 8GB (4x2GB) DDR3 1600MHz
- Graphics: Gigabyte GeForce GTS 450 OC 1024MB GDDR5
Reply With Quote
Reply

Tags
control, guess, hacked

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Remote control of a system glennzo Servers & Networking 11 14th May 2008 09:08 AM
REAL BAD:My system hacked into :( satishir Security and Privacy 16 8th May 2008 05:00 AM
Fedora Core 3 System Hacked :( valdes Installation and Live Media 1 29th September 2006 02:54 PM
How do I control the system fan on the northbridge? jtp51 Using Fedora 0 27th March 2006 02:10 PM


Current GMT-time: 14:18 (Wednesday, 22-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat