Welcome to Linux Forums! With a comprehensive Linux Forum, information on various types of Linux software and many Linux Reviews articles, we have all the knowledge you need a click away, or accessible via our knowledgeable members.
Find the answer to your Linux question:
New to Linux Forums? Register here for free!
    Linux Forums > GNU Linux Zone > Linux Security > Need urgent help

Forgot Password?
 Linux Security   Discussion about keeping your machines secure, and the crackers out.

Site Navigation
Linux Articles
Linux Forums
Linux Downloads
Linux Hosting
Free Magazines
Job Board
IRC Chat
RSS Feeds


Linux Forum Topics
Linux Forums
Your Distro
Linux Resources
GNU Linux Zone
The Community
Reply
 
Thread Tools Display Modes
Old 06-07-2009   #1 (permalink)
Just Joined!
 
Join Date: Jun 2009
Location: San Jose, CA
Posts: 5
Need urgent help

Experts,

I am hosting a server at my home network (site:j i l t i n d o t c o m ) I am hosting only web server with php,mysql.

However, monitoring the router and switches, I am seeing some people are using this as a proxy server and/or proxy email server.

1) email: I used to get the following to my admin email
Undeliverable mail: Потеря документов по недобросовестным поставщикам
I see them 20 - 40 messages daily. It i still coming after doing this

service sendmail stop
chkconfig sendmail off
chkconfig sendmail --list
sendmail 0:off 1:off 2:off 3:off 4:off 5:off 6:off

2) Some people are also using this as proxy server, mainly from russia.
whenever I go rapidshare or megaupload, it says your ip is already downloading.
It is always saying this without any gap for the past 24 hours.


Please help me fix this

Thanks in advance
Jiltin

Note: This forum does not allow me to post ps -ef output.
But you can see this output here (remove spaces, convert dot=".", slash="/")

j i l t i n d o t c o m s l a s h p s e f d o t t x t
jiltin is offline  


Reply With Quote
Old 06-07-2009   #2 (permalink)
Linux Guru
 
Rubberman's Avatar
 
Join Date: Apr 2009
Location: I can be found either 40 miles west of Chicago, or in a galaxy far, far away.
Posts: 2,662
It sounds like your system has been hacked. You should shut it down, reboot without internet access. Clean the infected components of the system, install SELinux, and/or implement a firewall. Your web server configuration also needs to be locked down, otherwise you are susceptible to reinfection.

One last point is that your web server pages have likely been subverted and are infecting your clients when they access your web pages. You need to clean them by reinstalling all of your web pages and scripts.
__________________
Sometimes, real fast is almost as good as real time.
Rubberman is offline   Reply With Quote
Old 06-08-2009   #3 (permalink)
Just Joined!
 
Join Date: Jun 2009
Location: San Jose, CA
Posts: 5
Quote:
Originally Posted by Rubberman View Post
It sounds like your system has been hacked. You should shut it down, reboot without internet access. Clean the infected components of the system, install SELinux, and/or implement a firewall. Your web server configuration also needs to be locked down, otherwise you are susceptible to reinfection.

One last point is that your web server pages have likely been subverted and are infecting your clients when they access your web pages. You need to clean them by reinstalling all of your web pages and scripts.
This is very likely issue. How can I find out whether the server is hacked?

I have Cent OS. "Clean the infected components"? How can I find out?

What should do? I do not know I shutdown email server. I see /var/log/secure no login attempts.

where to start?
jiltin is offline   Reply With Quote
Old 06-08-2009   #4 (permalink)
Just Joined!
 
Join Date: Jun 2009
Location: San Jose, CA
Posts: 5
netstat -tap gives
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name
tcp 0 0 master.jiltin.com:2208 *:* LISTEN 15743/hpiod
tcp 0 0 *:mdbs_daemon *:* LISTEN 15458/rpc.statd
tcp 0 0 *:mysql *:* LISTEN 15961/mysqld
tcp 0 0 *:sunrpc *:* LISTEN 15423/portmap
tcp 0 0 master.jiltin.com:ipp *:* LISTEN 15805/cupsd
tcp 0 0 master.jiltin.com:2207 *:* LISTEN 15779/python
tcp 0 0 *:http *:* LISTEN 16000/httpd
tcp 0 0 *:ssh *:* LISTEN 15794/sshd
tcp 0 0 *:https *:* LISTEN 16000/httpd
tcp 0 0 *csync-https *:* LISTEN 16000/httpd
tcp 0 444 ::ffff:192.168.0.100:ssh jiltin.com:tn-timing ESTABLISHED 17742/1
tcp 0 0 ::ffff:192.168.0.100:http 77-254-135-45.adsl.in:51625 TIME_WAIT -
tcp 0 128486 ::ffff:192.168.0.100:http c-98-215-155-227.:gemini-lm FIN_WAIT1 -
tcp 0 0 ::ffff:192.168.0.100:http jiltin.com:apollo-status TIME_WAIT -
tcp 0 0 ::ffff:192.168.0.100:http c-98-215-155-2ictrography FIN_WAIT2 -
tcp 0 0 ::ffff:192.168.0.100:http jiltin.com:cnrp TIME_WAIT -
tcp 0 0 ::ffff:192.168.0.100:http jiltin.com:apollo-cc TIME_WAIT -
tcp 0 0 ::ffff:192.168.0.100:http jiltin.com:de-spot TIME_WAIT -
tcp 0 0 ::ffff:192.168.0.100:http jiltin.com:uadtc TIME_WAIT -
tcp 0 0 ::ffff:192.168.0.100:http jiltin.com:data-insurance TIME_WAIT -
tcp 0 0 ::ffff:192.168.0.100:http jiltin.com:qip-audup TIME_WAIT -
tcp 0 0 ::ffff:192.168.0.100:http jiltin.com:sabams TIME_WAIT -
tcp 0 0 ::ffff:192.168.0.100:http jiltin.com:smpp TIME_WAIT -
tcp 0 0 ::ffff:192.168.0.100:http jiltin.com:auris TIME_WAIT -
tcp 0 0 ::ffff:192.168.0.100:http jiltin.com:rbakcup1 TIME_WAIT -
tcp 0 0 ::ffff:192.168.0.100:http jiltin.com:veronica TIME_WAIT -
tcp 0 0 ::ffff:192.168.0.100:http jiltin.com:uacs TIME_WAIT -
tcp 0 0 ::ffff:192.168.0.100:http jiltin.com:ridgeway1 TIME_WAIT -
tcp 0 0 ::ffff:192.168.0.100:http 45.Red-83-60-149.:lnvstatus TIME_WAIT -
jiltin is offline   Reply With Quote
Old 06-08-2009   #5 (permalink)
Just Joined!
 
Join Date: Dec 2008
Location: Jakarta ID
Posts: 3
Send a message via Yahoo to p_nyet
Trying to check log of httpd access and error, attacker maybe not hacked into your system, but hacking into some website in your server.

Regards,
p_nyet is offline   Reply With Quote
Old 06-08-2009   #6 (permalink)
Just Joined!
 
Join Date: Jun 2009
Location: San Jose, CA
Posts: 5
Quote:
Originally Posted by p_nyet View Post
Trying to check log of httpd access and error, attacker maybe not hacked into your system, but hacking into some website in your server.

Regards,
To some extend, I could control the issue. Changed all the password, removed a proxy folders from my site (this shows something had happened). There were three proxy folders (http proxys), rebooted the server.

Normally, I used to have 5 to 20 concurrent users at my web site.

As of this time, the activities reduced after removing the proxy and email server. Need to explore more.

Please let know where to start in such case.
jiltin is offline   Reply With Quote
Old 06-08-2009   #7 (permalink)
Linux User
 
Join Date: Oct 2006
Location: arizona
Posts: 395
honestly, unless you want to worry about this for the next several years, just wipe and reinstall CentOS, and enable SELinux next time.
__________________
New to the internet, technical forums, or the hacker / open source community??
Read this to learn good posting habits http://www.catb.org/~esr/faqs/smart-questions.html

RHCT for RHEL version 4
echo "$whatever_youre_saying" > /dev/null
meton_magis is offline   Reply With Quote
Old 06-08-2009   #8 (permalink)
Just Joined!
 
Join Date: Jun 2009
Location: San Jose, CA
Posts: 5
I appreciate all the feedbacks.

Now the server looks fine. But, I would also follow the best practice suggested by meton_magis.

Thank you Rubberman, p_nyet and meton_magis
jiltin is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Free Magazines
Run Your Own Web Server Using Linux & Apache - Free 191 Page Preview
Learn about everything you'll need to build and maintain your Linux servers, and to deploy Web applications to them.
subscribe
Open Source Security Myths Dispelled
Dispel the five major myths surrounding Open Source Security and gain the tools necessary to make a truly informed decision for your IT organization
subscribe
InformationWeek
InformationWeek is the only newsweekly you'll need to stay on top of the latest developments in information technology.
subscribe



All times are GMT. The time now is 04:57 AM.






© 2000 - 2009 - All Rights Reserved - Property of  MAS Media

Content Relevant URLs by vBSEO 3.3.0 RC2