RE: IRC bot on MacOS
"Smith, Donald" <[email protected]> Fri, 22 Apr 2005 08:26:27 -0600
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <9921AB57EA49D242A076864C5F473D3C0180D225@itdene2km08.AD.QINTRA.COM> |
Bad guys have been building bot nets and bot controllers using macOSx. Most likely they brute forced an account by guessing a weak password and then used a local root exploit to escalate privs to root. Then they downloaded one of several UNIX root kits that can run on a macosX system. Pysbnc is a common IRC bouncer often used to hide the real IRC control channel. Personally I would wipe the drive and reinstall (do a back of data first). [email protected] giac > -----Original Message----- > From: [email protected] > [mailto:[email protected]] On Behalf Of Andrew Daviel > Sent: Friday, April 22, 2005 3:12 AM > To: [email protected] > Subject: [Intrusions] IRC bot on MacOS > > > > Found an IRC bot "psybnc" on a MacOS machine. I'm struggling > a bit as I don't know Macs and it got an automatic system > upgrade a few days ago which trashed any logfiles. I suspect > it's been running since before my network log rollover date, > keeping a low profile until recently. The system has a > firewall configured with a hole on 22 and 80; since Apple run > sshd with xinetd, the rogue process was able to grab the port > when it wasn't in use. > > So far I've disabled the backdoor/bot and blocked the machine > on our router, but I'm not sure what the Mac boot sequence is > to figure our how it's getting restarted, and I don't know > the original exploit. Someone mentioned PHP, but I don't see > any exposed PHP pages. There was a weak password on a user > acount, but the attackers got root to run the bot. No attempt > to hide as far as I can see. > > I could post network logs, but I think it's all boring IRC > and SSH encrypted control stuff. Still looking for file > timestamps etc., but as I say I think it's before the > rollover so I'm out of luck unless there's more than one guy > been trying. > > Anyone seen anything like this ? Any hints on tracing Mac > bootup (I'm basically a Linux person...) ? > > > -- > Andrew Daviel, TRIUMF, Canada > Tel. +1 (604) 222-7376 (Pacific Time) > [email protected] _______________________________________________ > Intrusions mailing list > [email protected] > http://www.dshield.org/mailman/listinfo/intrusions > _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions