Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Security and Privacy
FedoraForum Search

Forgot Password? Join Us!

Security and Privacy Sadly, malware, spyware, hackers and privacy threats abound in today's world. Let's be paranoid and secure our penguins, and slam the doors on privacy exploits.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 25th February 2008, 01:05 AM
FYT2008 Offline
Registered User
 
Join Date: Feb 2008
Posts: 3
Server Hacked 2 times/ Have no Clue



We are experiencing difficult times here. Yesterday we found our server hacked with links inserted all over the website ( check yourself here: www.x6.ro ( please note www.x6.ro dont use joomla, the index is done manuallyand they even modified this index as well ), www.k6.ro - you will see a software that want to download on your screen that ask for permission ) and the hackers also inserted alot of invisible links into the websites.

I spent then 10 hours reinstalling FEDORA ( + plesk ) on the server doing the following:

- delete permission 777
- blocked smtp connections ( cose we got even listed in XBL spam database with ip because of exploits )

- blocked ftp access for anyone

- changed root password ( very complex ) , changed each hosting account password with a complex password.

=======================

Now you can only connect through the server via SSH but the password was impossibility to crack so this is not an option to explain why we got hacked again.


Now I checked my server and it is hacked again.

I checked logs, nothing unusual but the site was hacked now.

If you can help mewith solving this mystery ( how I got hacked ) Iwill be very gratefull.


I can provide all info you need, LOGS, anything, just let me know what files you need or what type of linux commands you want me to run on the server ( note I am linux starter ).


1000 thanks if you can help me solve this. After the whole reinstall we still got hacked this is outrageous.'

You can check all LOGS I collected now from the server here www.x6.ro/loguri.zip

Last edited by FYT2008; 25th February 2008 at 01:09 AM.
Reply With Quote
  #2  
Old 25th February 2008, 01:23 AM
stevea's Avatar
stevea Offline
Registered User
 
Join Date: Apr 2006
Location: Ohio, USA
Posts: 8,302
Currently it looks like all your low ports are filtered except for 80. If it was hacked in this state then you must look to the web service as the problem

Certainly you must have gained some information from the logs and examining the changes.
Did you find when the hack files were created ?
Where the cron logs OK at this time ?
Was audit running ? (if not use it).

Never use ftp - it's hopelessly insecure.

I think you need to hear from an Apache/web-service security person.
best wishes.
Reply With Quote
  #3  
Old 25th February 2008, 01:24 AM
pete_1967 Online
Clueless in a Cuckooland
 
Join Date: Mar 2006
Location: Here now, elsewhere tomorrow.
Posts: 3,929
What kernel version your server is running? An exploit to elevate local user privileges to root in versions 2.6.17 to 2.6.24.1. Just one way in on your system.

Another is, even if your server is secure, insecure scripts your clients are running. Have you chrooted all clients?

I don't have time to look at the logs (it's late here) but someone else may.
Reply With Quote
  #4  
Old 25th February 2008, 01:28 AM
FYT2008 Offline
Registered User
 
Join Date: Feb 2008
Posts: 3
What I found now is the followinf lines from /log/secure
-----------
Feb 25 07:45:36 82-78-216-197 useradd[9076]: new user: name=boywonder, UID=10005, GID=2524, home=/var/www/vhosts/focusyourtarget.com/web_users/boywonder, shell=/bin/false

-----------

Someone during today added a new Plesk user to a hosted website.

THE STRANGE STUFF is that THE IP that did that ( 82-78-216-197 ) is MINE ( i mean the server IP )

The guy that did it had only 2 options:

1. a sort of script installed the website pages that can modify plesk

I cant imagine how he used the same server IP
Reply With Quote
  #5  
Old 25th February 2008, 01:39 AM
pete_1967 Online
Clueless in a Cuckooland
 
Join Date: Mar 2006
Location: Here now, elsewhere tomorrow.
Posts: 3,929
You seriously should pull the plug on that server and keep it off the network until you've solved the cause and patched it.

At least you have something to look into now, and check your kernel version if it's one of I mention above, it means bad boys got an account with you (or have cracked someone else's).
Reply With Quote
  #6  
Old 25th February 2008, 01:49 AM
FYT2008 Offline
Registered User
 
Join Date: Feb 2008
Posts: 3
I only use the account.

Wile reading the logs /var/log/messages came to this :

1. All connections are PROTO=TCP

2. Only 1 line PROTO=UDP ( this mean udp connection )

Feb 25 06:30:19 82-78-216-197 kernel: Inbound IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:14:2a:65:7d:ab:08:00 SRC=86.122.133.145 DST=255.255.255.255 LEN=49 TOS=0x00 PREC=0x00 TTL=128 ID=22804 PROTO=UDP SPT=1101 DPT=5200 LEN=29

This ip: 86.122.133.145 is the only one that connect via UDP to my server ( and I really dont know how this is possible, all UDP connections are closed )


aparently this ip is from the same town with me
Reply With Quote
Reply

Tags
clue, hacked, server, times or

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Display Server has been shutdown 6 times in 90 seconds rudra-b Using Fedora 1 28th September 2008 03:26 AM
server was hacked HELP hoskinsrick Security and Privacy 13 5th June 2008 05:21 PM
Server Hacked and the root password didn't work gmg2006 Using Fedora 29 30th November 2007 03:47 PM
Server Hacked fedorafan2 Using Fedora 11 1st November 2007 03:15 AM
I think my server has been hacked Skillz Security and Privacy 4 27th March 2007 07:47 AM


Current GMT-time: 17:14 (Thursday, 23-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat