RE: IRC bot on MacOS

"Smith, Donald" <[email protected]> Fri, 22 Apr 2005 08:26:27 -0600
Newsgroups gmane.comp.security.intrusions
Message-ID <9921AB57EA49D242A076864C5F473D3C0180D225@itdene2km08.AD.QINTRA.COM>
Bad guys have been building bot nets and bot controllers using macOSx.
Most likely they brute forced an account by guessing a weak password and
then used a local root exploit to escalate privs to root.
Then they downloaded one of several UNIX root kits that can run on a
macosX system.
Pysbnc is a common IRC bouncer often used to hide the real IRC control
channel.
Personally I would wipe the drive and reinstall (do a back of data
first).


[email protected] giac 

> -----Original Message-----
> From: [email protected] 
> [mailto:[email protected]] On Behalf Of Andrew Daviel
> Sent: Friday, April 22, 2005 3:12 AM
> To: [email protected]
> Subject: [Intrusions] IRC bot on MacOS
> 
> 
> 
> Found an IRC bot "psybnc" on a MacOS machine. I'm struggling 
> a bit as I don't know Macs and it got an automatic system 
> upgrade a few days ago which trashed any logfiles. I suspect 
> it's been running since before my network log rollover date, 
> keeping a low profile until recently.  The system has a 
> firewall configured with a hole on 22 and 80; since Apple run 
> sshd with xinetd, the rogue process was able to grab the port 
> when it wasn't in use.
> 
> So far I've disabled the backdoor/bot and blocked the machine 
> on our router, but I'm not sure what the Mac boot sequence is 
> to figure our how it's getting restarted, and I don't know 
> the original exploit. Someone mentioned PHP, but I don't see 
> any exposed PHP pages. There was a weak password on a user 
> acount, but the attackers got root to run the bot. No attempt 
> to hide as far as I can see.
> 
> I could post network logs, but I think it's all boring IRC 
> and SSH encrypted control stuff. Still looking for file 
> timestamps etc., but as I say I think it's before the 
> rollover so I'm out of luck unless there's more than one guy 
> been trying.
> 
> Anyone seen anything like this ? Any hints on tracing Mac 
> bootup (I'm basically a Linux person...) ?
> 
> 
> -- 
> Andrew Daviel, TRIUMF, Canada
> Tel. +1 (604) 222-7376  (Pacific Time)
> [email protected] _______________________________________________
> Intrusions mailing list
> [email protected] 
> http://www.dshield.org/mailman/listinfo/intrusions
> 

_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions