Welcome to Linux Forums!

With a comprehensive Linux Forum, information on various types of Linux software and many Linux Reviews articles, we have all the knowledge you need a click away, or accessible via our knowledgeable members.

Linux Forum ArticlesLinux ForumsLinux Forum DownloadsLinux Hosts
Home|Register|FAQ|Member List|Calendar|Unanswered Posts|Forum Rules|Today's Posts|Advanced Search|
SEARCH FOR IN
Go Back   Linux Forums > GNU Linux Zone > Linux Security
Reload this Page rootkit infected
Linux Forums
Linux Forums
Welcome To The Linux Forums!
Welcome to Linux Forums. We pride ourselves in being one of the largest Linux communities on the web, we encourage you to REGISTER on our forums and participate in the community. There are over 150,000 members ready to answer your questions. JOINING US today will allow you to make new posts, get support, send messages to other members and submit downloads to our downloads directory and many other great features!

Linux Security Discussion about keeping your machines secure, and the crackers out.

Reply
 
Thread Tools Display Modes
Old 04-19-2005   #1 (permalink)
kamtono
Just Joined!
 
Join Date: Feb 2004
Location: Indonesia
Posts: 84
rootkit infected

helo

1. my linux box is infected with suckit rootkit how to remove it
2. and how to replace with uninfected binaries (procps, init-scripts, may i do uninstall the rpm and replace with the new ?)
3. when i do shutdown -h now or shutdown -r now i got some error afterall


/dev/null RK_Init idt=0xc036f000, sct[]=0xc030a0f0
**** : can't find kmalloc()!

is it safe to reset from reset button ?

thanks for your concerned
kamtono is offline   Reply With Quote
Old 04-19-2005   #2 (permalink)
retired1af
Linux Enthusiast
 
Join Date: Mar 2005
Location: Republic of Texas
Posts: 732
If your system has been rooted, get it off line NOW.

As for just reinstalling binaries, how do you know what's been replaced with what? It needs to be totally formatted and reloaded from scratch. Otherwise, you may end up being rooted again because you missed a critical file that was replaced to allow access back into the system.
__________________
Registered Linux user #384279
retired1af is offline   Reply With Quote
Old 04-19-2005   #3 (permalink)
Flatline
Linux Guru
 
Flatline's Avatar
 
Join Date: Feb 2005
Posts: 2,205
SuckIT installs default built binary called "sk" as /sbin/init. SuckIT (if unmodified) will uninstall itself when you call the "sk" binary with argument "u". So "/sbin/init u" should unload SuckIT. This by no means means you're in the safe zone.

Use your rescue CD (often your installation cd) for any operations on that box. Don't boot from the kernel on your hard drive!

Basically, you have no idea what the person who has rootkitted you has done to your box, what backdoors they have opened, etc. The only way to be sure that you are safe after a rootkit infection is the three "R"s: repartition, reformat and re-install from scratch
__________________
There are two major products that come out of Berkeley: LSD and UNIX. We don't believe this to be a coincidence.

- Jeremy S. Anderson
Flatline is offline   Reply With Quote
Old 04-19-2005   #4 (permalink)
puntmuts
Linux Enthusiast
 
puntmuts's Avatar
 
Join Date: Dec 2004
Location: Republic Banana
Posts: 562
And as an addition to the reply of Flatline: update your system frequently after reinstall.
__________________
I\'m so tired .....
#200472
puntmuts is offline   Reply With Quote
Old 04-19-2005   #5 (permalink)
Martin from Dublin
Linux User
 
Martin from Dublin's Avatar
 
Join Date: Dec 2004
Location: Dublin, Rep. of Ireland
Posts: 378
Pardon my ignorance guys, but is SuckIT a kind of trojan that infects Linux? I've never heard of it before. Will Shorewall keep it out (I've just installed Shorewall thanks to Flatline).

Martin,

Dublin, Ireland
__________________
LINUX: Where do you want to go.......Tomorrow!

Registered Linux user 396633
Martin from Dublin is offline   Reply With Quote
Old 04-19-2005   #6 (permalink)
puntmuts
Linux Enthusiast
 
puntmuts's Avatar
 
Join Date: Dec 2004
Location: Republic Banana
Posts: 562
http://la-samhna.de/library/rootkits/list.html
__________________
I\'m so tired .....
#200472
puntmuts is offline   Reply With Quote
Old 04-19-2005   #7 (permalink)
loft306
Linux Guru
 
loft306's Avatar
 
Join Date: Oct 2003
Location: The DairyLand
Posts: 1,667
Quote:
Originally Posted by Martin from Dublin
Pardon my ignorance guys, but is SuckIT a kind of trojan that infects Linux? I've never heard of it before. Will Shorewall keep it out (I've just installed Shorewall thanks to Flatline).

Martin,

Dublin, Ireland
heh.... running not as root online will keep it out!!!
and not allowing root login through 'ssh'
also pick a complicated passwords in the next install.....with 1234@#$%^aoeuiAOEUI all used in the passwd especialy the root passwd
__________________
~Mike ~~~ Forum Rules
Testing? What's that? If it compiles, it is good, if it boots up, it is perfect. ~ Linus Torvalds
http://loft306.org
loft306 is offline   Reply With Quote
Old 04-19-2005   #8 (permalink)
retired1af
Linux Enthusiast
 
Join Date: Mar 2005
Location: Republic of Texas
Posts: 732
Quote:
Originally Posted by Martin from Dublin
Pardon my ignorance guys, but is SuckIT a kind of trojan that infects Linux? I've never heard of it before. Will Shorewall keep it out (I've just installed Shorewall thanks to Flatline).

Martin,

Dublin, Ireland
Not exactly, Martin. A root kit is a set of tools used by someone to maintain control of a system after he's broken into it.
__________________
Registered Linux user #384279
retired1af is offline   Reply With Quote
Old 04-20-2005   #9 (permalink)
Goran
Linux Newbie
 
Join Date: Jan 2004
Location: Belgrade, S&M
Posts: 177
Send a message via ICQ to Goran Send a message via MSN to Goran
You should really consider reinstalling from scratch. You can never be sure that the damage is repaired and all the backdoors are closed.
Goran is offline   Reply With Quote
Old 04-20-2005   #10 (permalink)
kamtono
Just Joined!
 
Join Date: Feb 2004
Location: Indonesia
Posts: 84
thank's for your response ...

actually, yesterday when i browsing form google i have this interactive link
[remove suckit rootkit] http://www.soohrt.org/stuff/linux/suckit/

regarding about to offline, sory i can't
Oh, yes i found /sbin/initsk12 but i do know where is the program's
about procps, autofs, init-scripts (i found when i do rpm -qi procps -- information what i read is package tools like ps, netstat, ls and many more)

#ls -l /sbin/init [TAB]
init initlog initsk12
kamtono is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT. The time now is 12:27 AM.

Powered by vBulletin 3.6.8 ©2000 - 2007, content relevant URLs by vBSEO, Property of Core Root.

Content Relevant URLs by vBSEO 3.0.0