Page 2 of 3 FirstFirst 123 LastLast
Results 11 to 20 of 21

Thread: My 8.04 LTS box was hacked

  1. #11
    Join Date
    Jan 2008
    Location
    /dev/null
    Beans
    2,793
    Distro
    Ubuntu 8.04 Hardy Heron

    Re: My 8.04 LTS box was hacked

    Quote Originally Posted by eldragon View Post
    on defense of the not-a-hacker posture.
    something similar happened to me on my notebook, i was reviewing different photomanagers, and gthumb was it (i dont remember which one exactly) moved some folders around when it hung up on me, i didnt realized until i killed the app and couldnt find anything anymore.
    maybe something of this sort happened to you too.
    its a good idea to move ports around. or disable password logins and allow only rsa(name?) logins. but thats quite cumbersome.

    on my case, i cannot afford a different port than 22 since univ wont allow every port. rsa is a pain in the rearend, (i use it with my notebook, but allow password logins just in case i need it). so i just use really strong passwords. (and remember them ala rainman).
    having backups on an external drive is a good idea too although a hacker with root access will be able to delete that if he pleases. (and finds it).
    Unless every user account on that machine has a strong password, you have effectively negated any gains you have made by setting up public key authentication.

  2. #12
    Join Date
    Jan 2006
    Beans
    59
    Distro
    Ubuntu 10.04 Lucid Lynx

    Re: My 8.04 LTS box was *not* hacked

    In reading over the responses, I guess my system was not hacked in to.
    As puptentacle (and others) pointed out, it does seem odd that someone would copy a folder to another drive, then delete the original.
    I do know that I installed HH (8.04) on the 6th or 7th of last week.
    Would the installation process have moved data from /home on the second drive to /home on the primary drive? My guess is that it would not.
    I only had 5 user folders. /mnt/oldhd is the path to get to the second hard drive. As an example:
    /mnt/oldhd/home/bob
    /mnt/oldhd/home/jane
    /mnt/oldhd/home/carol
    /mnt/oldhd/home/john
    /mnt/oldhd/home/jim

    ../home/bob had 50 MB of files and all of the others were empty (with the excpetion of the hidden . files)

    I found that /bob had been moved to /home/shawn (my folder) and there was nothing in /mnt/oldhd.

    It's possbile I could have backed up bob's folder under my folder, but I don't remember ever doing that - although I've lost a few brain cells over the last few months .

    daengbo: What is an "IDS"?

    Thanks,
    -Shawn

  3. #13
    Join Date
    Oct 2007
    Beans
    19

    Re: My 8.04 LTS box was hacked

    This is a very interesting post, as I've just had a related incident on one of my machines. Here is a snip of the auth.log file. It appears that someone was conducting a brute force login attack, and then bingo, they were able to login using the user id "guest". This was the original account that I created when doing a fresh install of 8.04. I created a password for sure for this account although perhaps it wasn't a very high quality password. But it seems to me that the attacker guessed my password on the first try, which seems doubtful. The thing that scares me is that I'm wondering if samba is using the same id (guest) for access.

    Once the attacker logged in it appears that he/she tried to run a root kit but there is no evidence that this was successful.

    Any comments would be much appreciated.

    Thanks,
    Terry

    May 4 19:07:42 crow sshd[24606]: Invalid user admin from 221.141.2.233
    May 4 19:07:42 crow sshd[24606]: PAM unable to dlopen(/lib/security/pam_smbpass.so)
    May 4 19:07:42 crow sshd[24606]: PAM [error: /lib/security/pam_smbpass.so: cannot open shared object file: No such file or directory]
    May 4 19:07:42 crow sshd[24606]: PAM adding faulty module: /lib/security/pam_smbpass.so
    May 4 19:07:42 crow sshd[24606]: pam_unix(sshd:auth): check pass; user unknown
    May 4 19:07:42 crow sshd[24606]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=221.141.2.233
    May 4 19:07:44 crow sshd[24606]: Failed password for invalid user admin from 221.141.2.233 port 42152 ssh2
    May 4 19:07:51 crow sshd[24608]: Invalid user test from 221.141.2.233
    May 4 19:07:51 crow sshd[24608]: PAM unable to dlopen(/lib/security/pam_smbpass.so)
    May 4 19:07:51 crow sshd[24608]: PAM [error: /lib/security/pam_smbpass.so: cannot open shared object file: No such file or directory]
    May 4 19:07:51 crow sshd[24608]: PAM adding faulty module: /lib/security/pam_smbpass.so
    May 4 19:07:51 crow sshd[24608]: pam_unix(sshd:auth): check pass; user unknown
    May 4 19:07:51 crow sshd[24608]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=221.141.2.233
    May 4 19:07:52 crow sshd[24608]: Failed password for invalid user test from 221.141.2.233 port 42631 ssh2
    May 4 19:07:59 crow sshd[24611]: PAM unable to dlopen(/lib/security/pam_smbpass.so)
    May 4 19:07:59 crow sshd[24611]: PAM [error: /lib/security/pam_smbpass.so: cannot open shared object file: No such file or directory]
    May 4 19:07:59 crow sshd[24611]: PAM adding faulty module: /lib/security/pam_smbpass.so
    May 4 19:07:59 crow sshd[24611]: Accepted password for guest from 221.141.2.233 port 43084 ssh2
    May 4 19:07:59 crow sshd[24613]: pam_unix(sshd:session): session opened for user guest by (uid=0)
    May 4 19:08:03 crow sshd[24613]: pam_unix(sshd:session): session closed for user guest

  4. #14
    Join Date
    Jan 2007
    Beans
    24

    Re: My 8.04 LTS box was hacked

    Yeh. He tried some passwords but they all failed. Make sure you use quite a strong password. And make sure any web services dont have permissions for /etc/shadow

  5. #15
    Join Date
    Jun 2006
    Location
    Switzerland
    Beans
    Hidden!
    Distro
    Kubuntu Jaunty Jackalope (testing)

    Re: My 8.04 LTS box was hacked

    and use deny host or fail2ban

  6. #16
    Join Date
    Jan 2006
    Beans
    59
    Distro
    Ubuntu 10.04 Lucid Lynx

    Re: My 8.04 LTS box was *not* hacked

    One thing I forgot to ask in my previous post:
    What is "polkituser" and why does it have a group id?

    I found some info concerning "polkit" ("policy kit"), but nothing about "polkituser".
    I deleted user and group "polkituser" from my system.
    -Shawn

  7. #17
    Join Date
    Aug 2006
    Beans
    841

    Re: My 8.04 LTS box was hacked

    Quote Originally Posted by Oldsoldier2003 View Post
    Unless every user account on that machine has a strong password, you have effectively negated any gains you have made by setting up public key authentication.
    im actually allowing ssh from 2 users, both are strong passwored.

    the rsa idea is just because i hate to type passwords all the time
    it wasnt set for security measures. but i get your point, and my post was actually misleading into thinking i was being running a more secure box.

  8. #18
    Join Date
    Jan 2008
    Beans
    85

    Lightbulb Re: My 8.04 LTS box was *not* hacked

    Quote Originally Posted by shawnerz View Post
    daengbo: What is an "IDS"?
    Intrusion Detection Software
    like snort and nessus
    but you don't need them (only if you have a secure sensitive network)
    they use alot of ressources (like AntiVirus)

  9. #19
    Join Date
    Jan 2006
    Beans
    59
    Distro
    Ubuntu 10.04 Lucid Lynx

    Re: My 8.04 LTS box was *NOT* hacked

    All,
    I just thought I'd give an update.
    In my ealier post I said that all of the /home folders under /mnt/oldhd/ was gone.
    The reason: I had a drive failure. The hard drive died.

    Not being able to get to /home coupled with auth.log entries that I didn't fully understand made me think my system was hacked.

    Thanks to everyone for their help.
    -Shawn

  10. #20
    Join Date
    Nov 2005
    Location
    South Yorkshire, UK
    Beans
    238
    Distro
    Xubuntu 10.04 Lucid Lynx

    Re: My 8.04 LTS box was hacked

    Quote Originally Posted by TerryT View Post
    7:42 crow sshd[24606]: Invalid user admin from 221.141.2.233
    May 4 19:07:42 crow sshd[24606]: PAM unable to dlopen(/lib/security/pam_smbpass.so)
    May 4 19:07:42 crow sshd[24606]: PAM [error: /lib/security/pam_smbpass.so: cannot open shared object file: No such file or directory]
    May 4 19:07:42 crow sshd[24606]: PAM adding faulty module: /lib/security/pam_smbpass.so
    May 4 19:07:42 crow sshd[24606]: pam_unix(sshd:auth): check pass; user unknown
    May 4 19:07:42 crow sshd[24606]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=221.141.2.233
    May 4 19:07:44 crow sshd[24606]: Failed password for invalid user admin from 221.141.2.233 port 42152 ssh2
    May 4 19:07:51 crow sshd[24608]: Invalid user test from 221.141.2.233
    May 4 19:07:51 crow sshd[24608]: PAM unable to dlopen(/lib/security/pam_smbpass.so)
    May 4 19:07:51 crow sshd[24608]: PAM [error: /lib/security/pam_smbpass.so: cannot open shared object file: No such file or directory]
    May 4 19:07:51 crow sshd[24608]: PAM adding faulty module: /lib/security/pam_smbpass.so
    May 4 19:07:51 crow sshd[24608]: pam_unix(sshd:auth): check pass; user unknown
    May 4 19:07:51 crow sshd[24608]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=221.141.2.233
    May 4 19:07:52 crow sshd[24608]: Failed password for invalid user test from 221.141.2.233 port 42631 ssh2
    May 4 19:07:59 crow sshd[24611]: PAM unable to dlopen(/lib/security/pam_smbpass.so)
    May 4 19:07:59 crow sshd[24611]: PAM [error: /lib/security/pam_smbpass.so: cannot open shared object file: No such file or directory]
    May 4 19:07:59 crow sshd[24611]: PAM adding faulty module: /lib/security/pam_smbpass.so
    May 4 19:07:59 crow sshd[24611]: Accepted password for guest from 221.141.2.233 port 43084 ssh2
    May 4 19:07:59 crow sshd[24613]: pam_unix(sshd:session): session opened for user guest by (uid=0)
    May 4 19:08:03 crow sshd[24613]: pam_unix(sshd:session): session closed for user guest
    Was the password something really simple like "guest" or "password". Maybe sheer luck?

Page 2 of 3 FirstFirst 123 LastLast

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •