dvlchd3
September 23rd, 2009, 03:43 AM
I followed the three sticky guides above to help increase security.
Installed snort-mysql with base (apache, mysql, php, etc)
Installed ossec with web interface
Installed AppArmor with several profiles
Installed checklog, portsentry, and chkrootkit.
Hardened Firefox - NoScript, disabled cookies, bfilter, etc.
Installed Firestarter
Now, after browsing at my local coffee shop, I realized I had been port scanned twice:
#5-(3-6) [snort] (portscan) UDP Portsweep 2009-09-22 11:12:22 192.168.1.103 192.168.1.255 Raw IP
#6-(3-7) [snort] (portscan) UDP Portsweep 2009-09-22 12:47:12 192.168.1.103 192.168.1.255 Raw IP
ossec did not blacklist the ip like it should have, and the port scan was successful. Infact, even when I use nmap, like in the example, from another computer, ossec does nothing.
Also, I ran chkrootkit, and a few things were different then after the initial install:
Searching for suspicious files and dirs, it may take a while...
/usr/lib/jvm/.java-6-openjdk.jinfo /usr/lib/jvm/java-6-sun-1.6.0.16/lib/visualvm/visualvm/.lastModified /usr/lib/jvm/java-6-sun-1.6.0.16/.systemPrefs /usr/lib/jvm/.java-6-sun.jinfo /usr/lib/firefox-3.0.14/.autoreg /usr/lib/xulrunner-1.9.0.14/.autoreg /lib/modules/2.6.28-15-generic/volatile/.mounted /lib/init/rw/.ramfs
Checking `bindshell'... INFECTED (PORTS: 15 24 6667 31337)
Checking `sniffer'... lo: not promisc and no packet sniffer sockets
wlan0: PACKET SNIFFER(/sbin/wpa_supplicant[3815], /sbin/dhclient3[6013], /usr/sbin/snort[7370])
The infected bindshell really scares me, not sure if it should.
Nmap results:
Starting Nmap 4.76 ( http://nmap.org ) at 2009-09-23 03:07 EDT
Initiating Parallel DNS resolution of 1 host. at 03:07
Completed Parallel DNS resolution of 1 host. at 03:07, 0.02s elapsed
Initiating SYN Stealth Scan at 03:07
Scanning 10.3.51.121 [1000 ports]
Discovered open port 80/tcp on 10.3.51.121
Discovered open port 79/tcp on 10.3.51.121
Discovered open port 6667/tcp on 10.3.51.121
Discovered open port 32771/tcp on 10.3.51.121
Discovered open port 143/tcp on 10.3.51.121
Discovered open port 119/tcp on 10.3.51.121
Discovered open port 1524/tcp on 10.3.51.121
Discovered open port 31337/tcp on 10.3.51.121
Discovered open port 2000/tcp on 10.3.51.121
Discovered open port 1080/tcp on 10.3.51.121
Discovered open port 1/tcp on 10.3.51.121
Discovered open port 12345/tcp on 10.3.51.121
Discovered open port 32774/tcp on 10.3.51.121
Discovered open port 111/tcp on 10.3.51.121
Discovered open port 32772/tcp on 10.3.51.121
Discovered open port 32773/tcp on 10.3.51.121
Completed SYN Stealth Scan at 03:07, 0.10s elapsed (1000 total ports)
Host 10.3.51.121 appears to be up ... good.
Interesting ports on 10.3.51.121:
Not shown: 984 closed ports
PORT STATE SERVICE
1/tcp open tcpmux
79/tcp open finger
80/tcp open http
111/tcp open rpcbind
119/tcp open nntp
143/tcp open imap
1080/tcp open socks
1524/tcp open ingreslock
2000/tcp open callbook
6667/tcp open irc
12345/tcp open netbus
31337/tcp open Elite
32771/tcp open sometimes-rpc5
32772/tcp open sometimes-rpc7
32773/tcp open sometimes-rpc9
32774/tcp open sometimes-rpc11
Read data files from: /usr/share/nmap
Nmap done: 1 IP address (1 host up) scanned in 0.37 seconds
Raw packets sent: 1000 (44.000KB) | Rcvd: 2016 (84.704KB)
Where the heck did all those open ports come from!?!?!?
So, I'm rather confused as to what happened. I made attempts to strengthen the security of my system, however, it kind of seems like it has lessened??
So my question is, what does all of this mean, and where do I go from here?
Installed snort-mysql with base (apache, mysql, php, etc)
Installed ossec with web interface
Installed AppArmor with several profiles
Installed checklog, portsentry, and chkrootkit.
Hardened Firefox - NoScript, disabled cookies, bfilter, etc.
Installed Firestarter
Now, after browsing at my local coffee shop, I realized I had been port scanned twice:
#5-(3-6) [snort] (portscan) UDP Portsweep 2009-09-22 11:12:22 192.168.1.103 192.168.1.255 Raw IP
#6-(3-7) [snort] (portscan) UDP Portsweep 2009-09-22 12:47:12 192.168.1.103 192.168.1.255 Raw IP
ossec did not blacklist the ip like it should have, and the port scan was successful. Infact, even when I use nmap, like in the example, from another computer, ossec does nothing.
Also, I ran chkrootkit, and a few things were different then after the initial install:
Searching for suspicious files and dirs, it may take a while...
/usr/lib/jvm/.java-6-openjdk.jinfo /usr/lib/jvm/java-6-sun-1.6.0.16/lib/visualvm/visualvm/.lastModified /usr/lib/jvm/java-6-sun-1.6.0.16/.systemPrefs /usr/lib/jvm/.java-6-sun.jinfo /usr/lib/firefox-3.0.14/.autoreg /usr/lib/xulrunner-1.9.0.14/.autoreg /lib/modules/2.6.28-15-generic/volatile/.mounted /lib/init/rw/.ramfs
Checking `bindshell'... INFECTED (PORTS: 15 24 6667 31337)
Checking `sniffer'... lo: not promisc and no packet sniffer sockets
wlan0: PACKET SNIFFER(/sbin/wpa_supplicant[3815], /sbin/dhclient3[6013], /usr/sbin/snort[7370])
The infected bindshell really scares me, not sure if it should.
Nmap results:
Starting Nmap 4.76 ( http://nmap.org ) at 2009-09-23 03:07 EDT
Initiating Parallel DNS resolution of 1 host. at 03:07
Completed Parallel DNS resolution of 1 host. at 03:07, 0.02s elapsed
Initiating SYN Stealth Scan at 03:07
Scanning 10.3.51.121 [1000 ports]
Discovered open port 80/tcp on 10.3.51.121
Discovered open port 79/tcp on 10.3.51.121
Discovered open port 6667/tcp on 10.3.51.121
Discovered open port 32771/tcp on 10.3.51.121
Discovered open port 143/tcp on 10.3.51.121
Discovered open port 119/tcp on 10.3.51.121
Discovered open port 1524/tcp on 10.3.51.121
Discovered open port 31337/tcp on 10.3.51.121
Discovered open port 2000/tcp on 10.3.51.121
Discovered open port 1080/tcp on 10.3.51.121
Discovered open port 1/tcp on 10.3.51.121
Discovered open port 12345/tcp on 10.3.51.121
Discovered open port 32774/tcp on 10.3.51.121
Discovered open port 111/tcp on 10.3.51.121
Discovered open port 32772/tcp on 10.3.51.121
Discovered open port 32773/tcp on 10.3.51.121
Completed SYN Stealth Scan at 03:07, 0.10s elapsed (1000 total ports)
Host 10.3.51.121 appears to be up ... good.
Interesting ports on 10.3.51.121:
Not shown: 984 closed ports
PORT STATE SERVICE
1/tcp open tcpmux
79/tcp open finger
80/tcp open http
111/tcp open rpcbind
119/tcp open nntp
143/tcp open imap
1080/tcp open socks
1524/tcp open ingreslock
2000/tcp open callbook
6667/tcp open irc
12345/tcp open netbus
31337/tcp open Elite
32771/tcp open sometimes-rpc5
32772/tcp open sometimes-rpc7
32773/tcp open sometimes-rpc9
32774/tcp open sometimes-rpc11
Read data files from: /usr/share/nmap
Nmap done: 1 IP address (1 host up) scanned in 0.37 seconds
Raw packets sent: 1000 (44.000KB) | Rcvd: 2016 (84.704KB)
Where the heck did all those open ports come from!?!?!?
So, I'm rather confused as to what happened. I made attempts to strengthen the security of my system, however, it kind of seems like it has lessened??
So my question is, what does all of this mean, and where do I go from here?