RE: Visited by a cracker

Mario Ohnewald <[email protected]>
Newsgroups gmane.comp.security.linux
Message-ID <[email protected]>
On Wed, 2004-07-14 at 20:10, Shay Wilson wrote:
> I'm a little confused.  There have been several suggestions to wipe the
> box and I'm not disagreeing, but there was no sign of any successful
> hack. 

You will _never_ know for sure...

> The cracker was given a shell by the administrator. He paid for it
> (with a stolen credit card).  I realize approaching the machine with
> caution and using administrative tools that are verified perhaps freshly
> installed from on a CD or another machine is a very good thing, but
> wiping the machine?

Use your backup. You do have a backup on such an important production
system, dont you?

> 
> If I wiped my production machines every time my logs showed that someone
> attempted to gain unauthorized access or elevate their privileges I'd
> never have a working machine. In fact within minutes of turning a
> machine on I'm hit with various malevolent apache requests of someone
> trying to gain access through an old exploit.

No need, to panic, just keep an eye on it. But this is diffrent to your
case, where someone actually was IN your system.

>  
> 
> Granted these were newer exploits and potentially more dangerous because
> a shell had already been granted. They were still patched against and
> unsuccessful. Why must we wipe?

To be _sure_.
I couldn't sleep until its wiped out.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.