hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Hosting Security and Technology : under attack, need some help
Reply

Hosting Security and Technology Configuring and optimizing web hosting servers and operating systems, developing administration scripts, building servers, protecting against hackers, and general security (SSL certificates, etc.)
Forum Jump

under attack, need some help

Reply Post New Thread In Hosting Security and Technology Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 04-26-2006, 07:27 PM
jethbrown jethbrown is offline
Junior Guru Wannabe
 
Join Date: Nov 2004
Location: Edmonton, Alberta
Posts: 90
*

under attack, need some help


Last week I was attacked on my Layered Server by someone known as nobody and they installed a mechbot. I did all the server security things mentioned here and what layered sent me. This is the results of the other day first, and then I will post todays issues, as their back. Any input would be helpful.

Last Weeks fixes:

Secured files from non-root users using:
chmod 0700 `which curl` 2>&-; chmod 0700 `which fetch` 2>&-; chmod 0700 `which wget` 2>&-

rkhunter ran results:
MD5
MD5 compared: 80
Incorrect MD5 checksums: 1 (Kudzu)

File scan
Scanned files: 309
Possible infected files: 0
Possible rootkits:


Scanning took 52 seconds

Found IRCD exploit in /temp directory in hidden directory .f

Removed all instances of MechEnergy (program used to scan remote systems) More info
about Energy Mech can be found at http://www.energymech.net/

The /tmp directory has been locked down by disabling file execution from it and by disabling the user
nobody from executing files.

/dev/varTmp /var/tmp ext3 loop,rw,nosuid,noexec,nodev,noatime 0 0
/dev/tmp /tmp ext3 loop,rw,nosuid,noexec 0 0

The following IP was the user that started the attack: 194.109.129.220 and has been blocked via IP Tables from the server
we will also be filing a report with the ISP owner and forwarding a copy of this report to the RCMP for review.

Disabled Direct root login and changed all administrative passwords on all accounts.

Today:
It seems it is a mechbot that is being put into it. We traced the attack
the other day to a .fa directory. Now there is another one. I ran the
commands you sent in prior emails. This is the results of a scan I did in
SSH:

/var/tmp:
drwxr-xr-x 2 nobody 1024 Apr 24 07:55 .data/

/var/tmp/.data:
-rwxrwxrwx 1 nobody 0 Apr 24 07:55 skiddos*

/tmp/.iroha_unix/scripts:
-rw-r--r-- 1 nobody 527 Sep 4 2001 action.fix.tcl
-rw-r--r-- 1 nobody 316833 Apr 22 10:16 adC.tcl
-rw-r--r-- 1 nobody 7813 Sep 4 2001 alltools.tcl
-rw-r--r-- 1 nobody 9795 Sep 19 2004 autobotchk
-rw-r--r-- 1 nobody 4443 Apr 20 08:36 away.tcl
-rw-r--r-- 1 nobody 2759 Sep 4 2001 botchk
-rw-r--r-- 1 nobody 1294 Sep 4 2001 cmd_resolve.tcl
-rw-r--r-- 1 nobody 2233 Sep 4 2001 compat.tcl
-rw-r--r-- 1 nobody 1939 Sep 4 2001 CONTENTS
-rw-r--r-- 1 nobody 3361 Apr 20 08:36 dns.tcl
-rw-r--r-- 1 nobody 10937 Sep 4 2001 getops.tcl
-rw-r--r-- 1 nobody 1712 Apr 12 06:57 identify.tcl
-rw-r--r-- 1 nobody 3890 Sep 4 2001 klined.tcl
-rw-r--r-- 1 nobody 7440 Sep 4 2001 notes2.tcl
-rw-r--r-- 1 nobody 9878 Apr 8 23:44 portchk.tcl
-rw-r--r-- 1 nobody 13638 Sep 4 2001 ques5.tcl
-rw-r--r-- 1 nobody 52091 Sep 4 2001 sentinel.tcl
-rw-r--r-- 1 nobody 9728 Sep 4 2001 userinfo.tcl
-rw-r--r-- 1 nobody 22801 Sep 4 2001 weed


This is a Unix server with WHM 10.8.0 cPanel 10.8.1-S114, Fedora i686 - WHM X v3.1.0

There are 2 users with very secure passwords to login to SSH, and then they need to su to root with a 25 character password which we changed on last weeks attacks, just as a precaution.

Any input would be appreciated.

__________________
Jim Brown, BSc
Alberta Internet Host Providers Ltd.


Reply With Quote


Sponsored Links
  #2  
Old 04-26-2006, 08:27 PM
jethbrown jethbrown is offline
Junior Guru Wannabe
 
Join Date: Nov 2004
Location: Edmonton, Alberta
Posts: 90
ok I have one question. How can I make /tmp non executable? Is it a chmod command?

Thanks.

__________________
Jim Brown, BSc
Alberta Internet Host Providers Ltd.


Reply With Quote
  #3  
Old 04-26-2006, 08:42 PM
Servax Servax is offline
Aspiring Evangelist
 
Join Date: Mar 2005
Posts: 399
Since you have cPanel, you can try:

Code:
/scripts/securetmp

__________________
|| Dennis Liang,
|| ServaxNet LLC

Reply With Quote
Sponsored Links
Reply

Related posts from TheWhir.com
Title Type Date Posted
Spamhaus Blames Cyberbunker for the Largest Public DDoS Attack Ever Web Hosting News 2013-03-27 14:11:35
Web Hosting Talk Message Board Back Online Following DDoS Attack Web Hosting News 2012-09-12 11:59:42
Blogging Site LiveJournal Hit by Ongoing DDoS Attack Web Hosting News 2011-12-08 16:35:38
4Chan Website Back Online After Days of Sustained DDoS Attack Web Hosting News 2011-11-16 15:44:05
Web Host Netregistry Hit by DDoS Attack Web Hosting News 2011-09-26 14:11:33


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?