[Security-Discuss] Exploits
"Bob Puff@NLE" <bob-6dd4Sf22++lWk0Htik3J/[email protected]> Mon, 03 Apr 2006 16:24:29 -0400
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Message-ID | <[email protected]> |
Hi Guys, Looks like one of my (fully-patched) 9.2 boxes just got rooted by two things that I thought had been fixed a long time ago. It appears that they got in via the openssl-too-open exploit, and then used a ptrace exploit to get root. Could someone please confirm if these 9.2 modules are indeed vulnerable (as the advisorys seem to indicate that everything was fixed, but...): openssl-0.9.7b-5.1.92mdk libopenssl0.9.7-devel-0.9.7b-5.1.92mdk libopenssl0.9.7-0.9.7b-5.1.92mdk kernel-2.4.22.32mdk-1-1mdk I was alerted to this attack by seeing net-pf-14 errors in my logs. Logged in to see that I couldn't restart apache. I saw this running on port 80: # lsof -i:80 COMMAND PID USER FD TYPE DEVICE SIZE NODE NAME ptrace24 5251 apache 4u IPv4 137712543 TCP *:http (LISTEN) hatori 5299 apache 4u IPv4 137712543 TCP *:http (LISTEN) CROND 5599 apache 4u IPv4 137712543 TCP *:http (LISTEN) Can't seem to find ptrace24, CROND, or hatori, but they were running. Example: # ps ax | grep CRON 19263 ? S 0:00 ./CROND I changed the SSL config to: SSLCipherSuite ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:!SSLv2:+EXP:+eNULL ...hoping that fixes the way they got in. Any ideas on fixing the ability to run the ptrace exploit? Bob I changed the + ____________________________________________________ Want to buy your Pack or Services from Mandriva? Go to http://store.mandriva.com Join the Club : http://www.mandrivaclub.com ____________________________________________________