11
bugmenot
Re: Simiens Crew??? wtf
  • 2005/2/2 21:21

  • bugmenot

  • Just popping in

  • Posts: 8

  • Since: 2004/10/23


My site was hacked too (they changed my index page). And I am running awstats. I don't know for sure if that's what caused them to gain access or not, as I am not the admin, just a user. I have sent their tech support an email, waiting to hear back.

12
dormouse
Re: Simiens Crew??? wtf
  • 2005/2/4 12:22

  • dormouse

  • Just popping in

  • Posts: 1

  • Since: 2005/2/4 9


Our site was hacked too.
We are pretty sure, that awstat was used to break in initially (see: http://forum.zone-h.org/viewtopic.php?t=1902).
We dont know yet how they proceeded to become root.
It is NOT only graffity: they installed a root kit and replaced the kernel.
The root kit consists of patched ls, ps, pstree, netstat, ifconfig (...) and (at least one) changed shared library (still checking).
ifconfig was replaced by a version which opens an unauthorized root backdoor through a non-priv tcp port.
The modified netstat hides this port; the modified ps hides the underlying daemon. ls hides the files.
The kernel was modified to not allow move or replacement of the corrupted executables (guess: by a special uid/gid combination).

If your site was attacked - please ensure, that its definitely only the apache config or home page, that was changed - otherwise, it could be used for further fraud/attacks.
Do not trust any command - before analyzing; make sure you have downloaded trusted versions of the above mentioned commands (use statically linked versions, as libc.so and friends could also be affected)
BTW: Our linux was pretty up-to-date w.r.t. security fixes (except for awstats - sigh).

regards

Login

Who's Online

399 user(s) are online (297 user(s) are browsing Support Forums)


Members: 0


Guests: 399


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: Nov 30
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits