hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Dedicated Server : hacking 101
Reply

Dedicated Server Current and past experiences with dedicated server providers, bandwidth, and server performance. Review managed and unmanaged dedicated web servers, discuss both Windows and Unix dedicated server solutions, and discuss dedicated hosting providers. If your service is unavailable, please click here.
Forum Jump

hacking 101

Reply Post New Thread In Dedicated Server Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 05-03-2011, 05:30 PM
themedia themedia is offline
Aspiring Evangelist
 
Join Date: Aug 2007
Posts: 423
*

hacking 101


Okay let's say that hypothetically speaking, you want to upgrade a server. You order the server, and it gets delivered in the morning, after some delays. You login to the freebsd 8.2 64bit box, and you start to upgrade ports, and then recompile kernel, and upgrade to the latest patch level.

Then you install cPanel, and once you setup the system mails to your catchall mailbox, you notice something weird. A binary exim-update is running on the server every minute, trying to open a reverse shell to another server.

You become puzzled, and you start checking the logs.

What do you see ?

Well you see that only ip addresses from the datacenter connected to the box besides you. You also notice that who connected to the server did "unset HISTSAVE" (thanks csh shell log timestamps), you also notice that the exim-update binary was uploaded to the box within 15 minutes from when that login from the datacenter was made.

You also notice that the reverse shell tries to connect to a server owned by the datacenter.

Let's also say that you have not used your normal admin/root password when you asked for the server installation, because that's a password you setup only after the box is completed by you, but a complete unique password, that only you and the datacenter guys knew.

Assuming the facts above. What picture do you get in your head? Any logical explanation ?

For the argument's sake, the server mentioned is already being reinstalled now, by one of the techs i actually trust but ... just saying ... how would you feel ?

__________________
XSBackup - keeping your data secure. Offsite redundant backups - RAID6 storage / rSync / SSH / FTP access. Whitelabel services / Reseller accounts available.
NEW! - If you need awesome admins to secure, optimize and maintain your servers, you're in the right place.

Reply With Quote


Sponsored Links
  #2  
Old 05-03-2011, 05:38 PM
TinyVox TinyVox is offline
Junior Guru
 
Join Date: Jan 2010
Location: so cal
Posts: 232
As weird as this may sound....this is not uncommon. I've had the same thing happened to me a while back from a vps provider. It's usually that the provider outsource their support and their support staff makes a little cash by giving away your credentials.

I also didn't jump into conclusions, but I did leave the vps provider.

On another note, I do like your xsbackup pricing

Reply With Quote
  #3  
Old 05-03-2011, 05:40 PM
bear bear is online now
Community Leader
 
Join Date: Oct 2002
Location: cognito
Posts: 17,323
What did the DC have to say about this?

__________________
Have problems (don't we all)? Head over to the help desk
If at first you don't succeed, that's one data point.


Reply With Quote
Sponsored Links
  #4  
Old 05-03-2011, 05:53 PM
themedia themedia is offline
Aspiring Evangelist
 
Join Date: Aug 2007
Posts: 423
Well the dc said that they have a script that puts up the ip aliases, and that script does the unset ... but as far as i know, any shell script if you run it in a shell, you will get logged the initial command that you did to run the script, not the individual commands the script does like ...

./script and the script has several commands in it, the .history or .bash_history will only show ./script as logged command, and not the individual commands that i have listed in the script.

as for the rest ... they are looking into it. (they found nothing so far. i asked them to investigate who logged in at that time, and who owns the other server the reverse shell was supposed to connect to.) it's a pretty fun story heh ? I guess i have to say thanks to my background - i come from shell hosting - had to deal with all kinds of kiddies, exploits, hack attempts .

thanks for liking our pricing try it out, and see if you like it even more

__________________
XSBackup - keeping your data secure. Offsite redundant backups - RAID6 storage / rSync / SSH / FTP access. Whitelabel services / Reseller accounts available.
NEW! - If you need awesome admins to secure, optimize and maintain your servers, you're in the right place.


Last edited by themedia; 05-03-2011 at 05:56 PM.
Reply With Quote
  #5  
Old 05-03-2011, 05:56 PM
quantumphysics quantumphysics is offline
MACBOOKS EVERYWHEREEEEEEEEEEEE
 
Join Date: Mar 2009
Posts: 3,804
"You also notice that the reverse shell tries to connect to a server owned by the datacenter."

Is it actually owned by the datacenter (like RWHOIS/rdns -> .office, .support, CompanyName Internal Infrastructure) or is it maybe another compromised system autoscanning its own subnet?

__________________
mirACL: firewalls in software.

Reply With Quote
  #6  
Old 05-03-2011, 05:59 PM
themedia themedia is offline
Aspiring Evangelist
 
Join Date: Aug 2007
Posts: 423
Quote:
Originally Posted by quantumphysics View Post
"You also notice that the reverse shell tries to connect to a server owned by the datacenter."

Is it actually owned by the datacenter (like RWHOIS/rdns -> .office, .support, CompanyName Internal Infrastructure) or is it maybe another compromised system autoscanning its own subnet?
no. the thing is the backdoor doesn't like perl threaded. i had to install perl threaded on this box, and therefore it was not running properly.

i analysed the backdoor, and it was only supposed to open a reverse shell, and connect to a hard coded ip address(the server owned by the datacenter), not scan a subnet. i can make the difference between a scanner and a backdoor.

__________________
XSBackup - keeping your data secure. Offsite redundant backups - RAID6 storage / rSync / SSH / FTP access. Whitelabel services / Reseller accounts available.
NEW! - If you need awesome admins to secure, optimize and maintain your servers, you're in the right place.

Reply With Quote
Reply

Similar Threads
Thread Thread Starter Forum Replies Last Post
df -h (how 101% use) mygethosted Hosting Security and Technology 3 10-25-2009 12:34 PM
Hacking server !!! not hacking accounts anymore AndyJ Hosting Security and Technology 22 01-24-2005 04:53 PM
Chinese 101 kohashi Web Hosting Lounge 11 08-08-2003 04:22 PM
Hacking 101: Blocking people from hacker countries? troff Dedicated Server 12 07-26-2002 11:30 PM

Related posts from TheWhir.com
Title Type Date Posted
Alleged Sony Pictures LulzSec Hacker Arrested in Arizona Web Hosting News 2011-09-23 14:29:09
Sony Names Philip R. Reitinger SVP and Chief Information Security Officer Web Hosting News 2011-09-06 18:55:18
Hacker Group Lulzsec Disbands After 50 Days, Posts One Final Data Dump Web Hosting News 2011-06-27 14:59:08
Hacker Group LulzSec Leaks Arizona Law Enforcement Data Web Hosting News 2011-06-24 14:14:28
SOCA Website Back Online After LulzSec DDoS Attack Web Hosting News 2011-06-21 15:06:30


Tags
hacked server, hacking 101, puzzled

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?