Index: [Article Count Order] [Thread]

Date:  Fri, 13 Jan 2006 09:30:38 +0100
From:  "Banda" <banda_mlcube (at mark) net.hr>
Subject:  [coba-e:03843] Re: more hacked
To:  <coba-e (at mark) bluequartz.org>
Message-Id:  <1cbd01c6181b$a1f2def0$1945a8c0@vbanda>
References:  <6953798.1136847623832.JavaMail.adm-moff (at mark) moffice5.nsc.no> <15ac01c616b6$6cde6150$1945a8c0 (at mark) vbanda> <1137107343.2754.10.camel (at mark) evon160.safranmedia.com>
X-Mail-Count: 03843

> Yes the compromised server was a fc1+bq. We have a few websites running
> on this server and we have a feeling that the user might have come
> through one of the php-enabled sites. One had a forum on it, we've
> removed that one, but the backdoor is still active (the server is
> unavailable for a few hours every night now).
>
> Today I was working on the server (ssh) when I noticed that an -bash job
> was connected to apache (ps -aux). I have a feeling that this might have
> something to do with the hack.
> I have a feeling that there is an insecure php-script running on the
> server that the hacker has used. We've now turned safe mode on. (Btw:
> with safe mode on the bq admin doesn't work, which is a bad thing).
> BlueQuartz should run in php safe mode.
>
> I ran chkrootkit and also found that there was a worm going on. That was
> the last thing I found out before the connection froze and I wasn't able
> to get in touch with the server. But I'll try again at 05.00 tomorrow
> morning.

Great info, thanks!  Regarding running BQ in php safe mode, I don't think
that it will ever be possible without major rewrite. BQ admin application
must have possibility of r+w to system (usually root) files, restart
daemons, etc..

Cheers,
Vlado