Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Security and Privacy
FedoraForum Search

Forgot Password? Join Us!

Security and Privacy Sadly, malware, spyware, hackers and privacy threats abound in today's world. Let's be paranoid and secure our penguins, and slam the doors on privacy exploits.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 25th February 2005, 07:21 AM
byw's Avatar
byw Offline
Registered User
 
Join Date: Aug 2004
Location: North Bucks, England
Age: 23
Posts: 47
Have I been attacked?

Hi

I have an apache webserver on FC3, I was browsing the server-status of it and came across this, should be on one line:
9-0 5885 0/13/13 _ 0.03 12125 0 0.0 0.03 0.03 24.172.78.10 phoenix GET /scripts/..%255c%255c../winnt/system32/cmd.exe?/c+dir

What does this mean? I have been hacked?

Byron Williams
byron@byronwilliams.me.uk
Reply With Quote
  #2  
Old 25th February 2005, 08:01 AM
spiderhosts Offline
Registered User
 
Join Date: Feb 2005
Posts: 102
Someone seems to be scanning your machine and trying to run the cmd.exe command which is the command prompt used on windows NT.

Since you are running Fedora this is completely irrelevant for you but I would recommend that you do not dismiss this incident. This is a reminder that people up to no good are constanly scanning your machine and should be taken as an excuse to harden it....

Just my 2 cent's

Bechara Hitti
__________________
SpiderHosts.com LLC
www.spiderhosts.com
www.spiderhosts.net
Reply With Quote
  #3  
Old 25th February 2005, 03:29 PM
Ned Offline
Registered User
 
Join Date: May 2004
Location: UK
Posts: 399
This is just script kiddies doing their stuff. The first good thing is that you obviously check your logs, something that's essential if you're running an publically accessible service such as http. Also, at the very least, make sure your machine stays up to date with all the latest security patches.

If you want to further harden your security, use strong passwords (if you're not doing so already) and change them frequently. Turn off or disable any services that you don't need. Also consider running any machine with publically accessible services in a DMZ so if it does get hacked you minimise the damage to just one machine, not your whole lan.

Ned
Reply With Quote
  #4  
Old 25th February 2005, 09:38 PM
byw's Avatar
byw Offline
Registered User
 
Join Date: Aug 2004
Location: North Bucks, England
Age: 23
Posts: 47
Cool thanks, just got a little paranoid and I think just in-case I'll change my set of passwords!

Byron Williams
Reply With Quote
  #5  
Old 25th February 2005, 09:51 PM
awdac Offline
Registered User
 
Join Date: Feb 2005
Location: Athens, GA
Posts: 352
Actually, that looks more like the footprints of a worm rather than someone particularly targeting you, if it makes you feel any better. Take the others' advice though, and you should be fine.
__________________
Registered Linux User #240607
2001-11-02 03:17:23
Reply With Quote
  #6  
Old 26th February 2005, 04:57 AM
w5set Offline
Registered User
 
Join Date: Feb 2005
Location: ark n saw out in the sticks
Posts: 2,316
As long as they are using a M$ exploit to try and make a zombie out your Linux server, you don't have much to worry about. If you have a SSH server running,there is always a chance they can gain access to it. Well SSH and a few other RPC types running they have a chance. Wait until they try the 4092+ character buffer overflow exploit and look then at what your log shows! That makes for one LONG line in the log file.
Who said--Build it and they will come?
Reply With Quote
Reply

Tags
attacked

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Would it be the PC attacked ? satimis Security and Privacy 2 9th July 2008 08:11 AM
port being attacked? or spyware? Wiles Security and Privacy 3 23rd September 2007 07:12 AM
Help! my computer was attacked by hacker cyhsieh Security and Privacy 4 28th December 2005 06:09 PM
I think I was attacked, what to do?? odiseo77 Security and Privacy 9 24th April 2005 06:37 AM


Current GMT-time: 08:19 (Wednesday, 22-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat