Welcome to Linux Forums! With a comprehensive Linux Forum, information on various types of Linux software and many Linux Reviews articles, we have all the knowledge you need a click away, or accessible via our knowledgeable members.
Find the answer to your Linux question:
New to Linux Forums? Register here for free!
    Linux Forums > GNU Linux Zone > Linux Security > rootkit infected
 Linux Security   Discussion about keeping your machines secure, and the crackers out.

Site Navigation
Linux Articles
Linux Forums
Linux Downloads
Linux Hosting
Free Magazines
Job Board
IRC Chat
Linux Forum Topics
Linux Forums
Your Distro
Linux Resources
GNU Linux Zone
The Community
Reply
 
Thread Tools Display Modes
Old 04-19-2005   #1 (permalink)
Just Joined!
 
Join Date: Feb 2004
Location: Indonesia
Posts: 84
rootkit infected

helo

1. my linux box is infected with suckit rootkit how to remove it
2. and how to replace with uninfected binaries (procps, init-scripts, may i do uninstall the rpm and replace with the new ?)
3. when i do shutdown -h now or shutdown -r now i got some error afterall


/dev/null RK_Init idt=0xc036f000, sct[]=0xc030a0f0
**** : can't find kmalloc()!

is it safe to reset from reset button ?

thanks for your concerned
kamtono is offline  

Reply With Quote
Old 04-19-2005   #2 (permalink)
Linux Enthusiast
 
Join Date: Mar 2005
Location: Republic of Texas
Posts: 732
If your system has been rooted, get it off line NOW.

As for just reinstalling binaries, how do you know what's been replaced with what? It needs to be totally formatted and reloaded from scratch. Otherwise, you may end up being rooted again because you missed a critical file that was replaced to allow access back into the system.
__________________
Registered Linux user #384279
retired1af is offline   Reply With Quote
Old 04-19-2005   #3 (permalink)
Linux Guru
 
Flatline's Avatar
 
Join Date: Feb 2005
Posts: 2,204
SuckIT installs default built binary called "sk" as /sbin/init. SuckIT (if unmodified) will uninstall itself when you call the "sk" binary with argument "u". So "/sbin/init u" should unload SuckIT. This by no means means you're in the safe zone.

Use your rescue CD (often your installation cd) for any operations on that box. Don't boot from the kernel on your hard drive!

Basically, you have no idea what the person who has rootkitted you has done to your box, what backdoors they have opened, etc. The only way to be sure that you are safe after a rootkit infection is the three "R"s: repartition, reformat and re-install from scratch
__________________
There are two major products that come out of Berkeley: LSD and UNIX. We don't believe this to be a coincidence.

- Jeremy S. Anderson
Flatline is offline   Reply With Quote
Old 04-19-2005   #4 (permalink)
Linux Enthusiast
 
puntmuts's Avatar
 
Join Date: Dec 2004
Location: Republic Banana
Posts: 562
And as an addition to the reply of Flatline: update your system frequently after reinstall.
__________________
I\'m so tired .....
#200472
puntmuts is offline   Reply With Quote
Old 04-19-2005   #5 (permalink)
Linux User
 
Martin from Dublin's Avatar
 
Join Date: Dec 2004
Location: Dublin, Rep. of Ireland
Posts: 383
Pardon my ignorance guys, but is SuckIT a kind of trojan that infects Linux? I've never heard of it before. Will Shorewall keep it out (I've just installed Shorewall thanks to Flatline).

Martin,

Dublin, Ireland
__________________
LINUX: Where do you want to go.......Tomorrow!

Registered Linux user 396633
Martin from Dublin is offline   Reply With Quote
Old 04-19-2005   #6 (permalink)
Linux Enthusiast
 
puntmuts's Avatar
 
Join Date: Dec 2004
Location: Republic Banana
Posts: 562
__________________
I\'m so tired .....
#200472
puntmuts is offline   Reply With Quote
Old 04-19-2005   #7 (permalink)
Linux Guru
 
loft306's Avatar
 
Join Date: Oct 2003
Location: The DairyLand
Posts: 1,666
Quote:
Originally Posted by Martin from Dublin
Pardon my ignorance guys, but is SuckIT a kind of trojan that infects Linux? I've never heard of it before. Will Shorewall keep it out (I've just installed Shorewall thanks to Flatline).

Martin,

Dublin, Ireland
heh.... running not as root online will keep it out!!!
and not allowing root login through 'ssh'
also pick a complicated passwords in the next install.....with 1234@#$%^aoeuiAOEUI all used in the passwd especialy the root passwd
__________________
~Mike ~~~ Forum Rules
Testing? What's that? If it compiles, it is good, if it boots up, it is perfect. ~ Linus Torvalds
http://loft306.org
loft306 is offline   Reply With Quote
Old 04-19-2005   #8 (permalink)
Linux Enthusiast
 
Join Date: Mar 2005
Location: Republic of Texas
Posts: 732
Quote:
Originally Posted by Martin from Dublin
Pardon my ignorance guys, but is SuckIT a kind of trojan that infects Linux? I've never heard of it before. Will Shorewall keep it out (I've just installed Shorewall thanks to Flatline).

Martin,

Dublin, Ireland
Not exactly, Martin. A root kit is a set of tools used by someone to maintain control of a system after he's broken into it.
__________________
Registered Linux user #384279
retired1af is offline   Reply With Quote
Old 04-20-2005   #9 (permalink)
Linux Newbie
 
Join Date: Jan 2004
Location: Belgrade, S&M
Posts: 177
Send a message via ICQ to Goran Send a message via MSN to Goran
You should really consider reinstalling from scratch. You can never be sure that the damage is repaired and all the backdoors are closed.
Goran is offline   Reply With Quote
Old 04-20-2005   #10 (permalink)
Just Joined!
 
Join Date: Feb 2004
Location: Indonesia
Posts: 84
thank's for your response ...

actually, yesterday when i browsing form google i have this interactive link
[remove suckit rootkit] http://www.soohrt.org/stuff/linux/suckit/

regarding about to offline, sory i can't
Oh, yes i found /sbin/initsk12 but i do know where is the program's
about procps, autofs, init-scripts (i found when i do rpm -qi procps -- information what i read is package tools like ps, netstat, ls and many more)

#ls -l /sbin/init [TAB]
init initlog initsk12
kamtono is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Free Magazines
Free Network Mapping Tool for Microsoft® Office Visio® Professional 2007 Users
Don't map your network by hand – let LANsurveyor Express for Microsoft Visio Professional 2007 automatically create network diagrams for you.
subscribe
Free eBook:"Vulnerability Management for Dummies"
Get all the Facts and See How to Implement a Successful Vulnerability Management Program.
subscribe
Google vs The World: The Battle of the Message Security Vendors
With such a powerful name behind it, Google Message Security stands out in a sea of products that do exactly the same thing - or so they say.
subscribe

Safe, Secure Backup


All times are GMT. The time now is 09:25 PM.






© 2000 - 2009 - All Rights Reserved - Property of  MAS Media

Content Relevant URLs by vBSEO 3.3.0 RC2