BlueAdept
08-13-2002, 11:13 AM
Well Im back up and running. Now with dual processors :)
I had gotten my system all re-setup except for my mail and up2date. I ran out of time and had to go to work. I figured I would do the up2date when I got home. From work I set up the mail and then got locked out of my system.
In that 8 hours I was at work, someone used the apache exploit and took over my system. All I can find that they did was to change the root password, wipe out the system logs (hehe they didnt find the backup logs I generate) and possibly got the shadow password file. They also installed some programs to give them access to the system.
I came home, booted into linux single mode and started my investigation. Saved all the info I had on him and the programs they left for me.
I couldnt beleive that within 8 hour that someone could find my system and take it over. I knew the exploit existed (as I had posted here) but I didnt expect them to find my system that quick after I had just done a re-install.
I re-wiped my system (just in case they did something I didnt know about) and re-installed everything. This time I kept my httpd services down along with ssh and smtp. The first thing I did after I put up the firewall again was to do up2date.
WORD TO THE WISE:
If you dont have a good firewall, get one (gShield is simple to set up). If you havent done up2date, you should. If you dont and you run apache web server, take it down.
I had gotten my system all re-setup except for my mail and up2date. I ran out of time and had to go to work. I figured I would do the up2date when I got home. From work I set up the mail and then got locked out of my system.
In that 8 hours I was at work, someone used the apache exploit and took over my system. All I can find that they did was to change the root password, wipe out the system logs (hehe they didnt find the backup logs I generate) and possibly got the shadow password file. They also installed some programs to give them access to the system.
I came home, booted into linux single mode and started my investigation. Saved all the info I had on him and the programs they left for me.
I couldnt beleive that within 8 hour that someone could find my system and take it over. I knew the exploit existed (as I had posted here) but I didnt expect them to find my system that quick after I had just done a re-install.
I re-wiped my system (just in case they did something I didnt know about) and re-installed everything. This time I kept my httpd services down along with ssh and smtp. The first thing I did after I put up the firewall again was to do up2date.
WORD TO THE WISE:
If you dont have a good firewall, get one (gShield is simple to set up). If you havent done up2date, you should. If you dont and you run apache web server, take it down.