HELP: mein samba wird attakiert
Posted: 2003-08-28 13:32
ich stellte gerade fest das mein samba server im netz von aussen angefriffen wird, die maschine ist extrem lahm geworden und mein ganzer sdsl anschluss ist zu 100% dicht
hier ein auszug aus den logs:
ich habe samba jetzt kurzerhand gestoppt und deinstalliert da ein upgrade mit apt nicht möglich war (to many connections), leider fand ich mit google nichts konkretes zum fehler nur smb source code..... wer kennt diesen fehler? was löst den fehler aus?
sniffen auf der nic ergab das der angreifer aus den usa angreift mit einer fetteren leitung als meine.... abuse mail an dne isp kamm zurück :evil:
hier ein auszug aus den logs:
Code: Select all
Aug 28 06:26:14 woodymaster smbd[24122]: [2003/08/28 06:26:14, 0] lib/util_str.c:safe_strcpy(876)
Aug 28 06:26:14 woodymaster smbd[24122]: ERROR: string overflow by 951 in safe_strcpy [~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P]
Aug 28 06:26:14 woodymaster smbd[24123]: [2003/08/28 06:26:14, 0] lib/util_str.c:safe_strcpy(876)
Aug 28 06:26:14 woodymaster smbd[24123]: ERROR: string overflow by 951 in safe_strcpy [~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P]
Aug 28 06:26:15 woodymaster smbd[24124]: [2003/08/28 06:26:15, 0] lib/util_str.c:safe_strcpy(876)
Aug 28 06:26:15 woodymaster smbd[24124]: ERROR: string overflow by 951 in safe_strcpy [~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P]
Aug 28 06:26:15 woodymaster smbd[24125]: [2003/08/28 06:26:15, 0] lib/util_str.c:safe_strcpy(876)
Aug 28 06:26:15 woodymaster smbd[24125]: ERROR: string overflow by 951 in safe_strcpy [~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P]
Aug 28 06:26:15 woodymaster smbd[24126]: [2003/08/28 06:26:15, 0] lib/util_str.c:safe_strcpy(876)
Aug 28 06:26:15 woodymaster smbd[24126]: ERROR: string overflow by 951 in safe_strcpy [~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P]
Aug 28 06:26:15 woodymaster smbd[24127]: [2003/08/28 06:26:15, 0] lib/util_str.c:safe_strcpy(876)
Aug 28 06:26:15 woodymaster smbd[24127]: ERROR: string overflow by 951 in safe_strcpy [~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P]
Aug 28 06:26:15 woodymaster smbd[24128]: [2003/08/28 06:26:15, 0] lib/util_str.c:safe_strcpy(876)
Aug 28 06:26:15 woodymaster smbd[24128]: ERROR: string overflow by 951 in safe_strcpy [~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P]
Aug 28 06:26:15 woodymaster smbd[24129]: [2003/08/28 06:26:15, 0] lib/util_str.c:safe_strcpy(876)
Aug 28 06:26:15 woodymaster smbd[24129]: ERROR: string overflow by 951 in safe_strcpy [~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P]
Aug 28 06:26:15 woodymaster smbd[24131]: [2003/08/28 06:26:15, 0] lib/util_str.c:safe_strcpy(876)
Aug 28 06:26:15 woodymaster smbd[24131]: ERROR: string overflow by 951 in safe_strcpy [~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P]
Aug 28 06:26:15 woodymaster smbd[24130]: [2003/08/28 06:26:15, 0] lib/util_str.c:safe_strcpy(876)
Aug 28 06:26:15 woodymaster smbd[24130]: ERROR: string overflow by 951 in safe_strcpy [~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P]
Aug 28 06:26:15 woodymaster smbd[24132]: [2003/08/28 06:26:15, 0] lib/util_str.c:safe_strcpy(876)
Aug 28 06:26:15 woodymaster smbd[24132]: ERROR: string overflow by 951 in safe_strcpy [~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P]
Aug 28 06:26:16 woodymaster smbd[24133]: [2003/08/28 06:26:16, 0] lib/util_str.c:safe_strcpy(876)
Aug 28 06:26:16 woodymaster smbd[24133]: ERROR: string overflow by 951 in safe_strcpy [~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P]
Aug 28 06:26:16 woodymaster smbd[24134]: [2003/08/28 06:26:16, 0] lib/util_str.c:safe_strcpy(876)
Aug 28 06:26:16 woodymaster smbd[24134]: ERROR: string overflow by 951 in safe_strcpy [~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P]
Aug 28 06:26:16 woodymaster smbd[24135]: [2003/08/28 06:26:16, 0] lib/util_str.c:safe_strcpy(876)
Aug 28 06:26:16 woodymaster smbd[24135]: ERROR: string overflow by 951 in safe_strcpy [~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P]
Aug 28 06:26:16 woodymaster smbd[24136]: [2003/08/28 06:26:16, 0] lib/util_str.c:safe_strcpy(876)
Aug 28 06:26:16 woodymaster smbd[24136]: ERROR: string overflow by 951 in safe_strcpy [~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P]
Aug 28 06:26:16 woodymaster smbd[24137]: [2003/08/28 06:26:16, 0] lib/util_str.c:safe_strcpy(876)
Aug 28 06:26:16 woodymaster smbd[24137]: ERROR: string overflow by 951 in safe_strcpy [~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P~P]
sniffen auf der nic ergab das der angreifer aus den usa angreift mit einer fetteren leitung als meine.... abuse mail an dne isp kamm zurück :evil: