Welcome to Linux Forums! With a comprehensive Linux Forum, information on various types of Linux software and many Linux Reviews articles, we have all the knowledge you need a click away, or accessible via our knowledgeable members.
Write an article for LinuxForums Today! Win Great Prizes!
Find the answer to your Linux question:
New to Linux Forums? Register here for free!
    Linux Forums > GNU Linux Zone > Linux Security > I have root kit

Forgot Password?
 Linux Security   Discussion about keeping your machines secure, and the crackers out.

Site Navigation
Linux Articles
Linux Forums
Linux Downloads
Linux Hosting
Free Magazines
Job Board
IRC Chat
RSS Feeds
Linux Forum Topics
Linux Forums
Your Distro
Linux Resources
GNU Linux Zone
The Community
Reply
 
Thread Tools Display Modes
Old 05-17-2005   #1 (permalink)
Just Joined!
 
Join Date: Mar 2005
Posts: 65
I have root kit

Hello,
I have a question about a rootkit, actually the one my friends business has. For certain reasons he does not want to reinstall the software, and he was dumb and didnt have a backup. He lives 200 miles away and I set up the server for him a long time ago. He does not know much about Linux the box just sits there and does what he needs. IF any changes need to be made I SSH into it and do whatever. Since I cant get access to the machine, I need to take care of this the hard way.

I know he has a rootkit, because he has some tools like 'ls' that are working strangly, and the root password changed on its own. How can I find what tools have been corrupted? Also how can I find the rootkit source code? Is there a certain directory it is stored in? of will a find or grep command beable to find it with certain key words? he has taken it off line and I can SSH to it from a different machine on his network. I will be going there in about 6 weeks to run a root kit detection tool on it, but I want to check and see the extent of the damage and to learn for myself more about root kits.

Please help however you can.
Thanks,
Art
baysidelinux is offline  



Reply With Quote
Old 05-17-2005   #2 (permalink)
Linux Enthusiast
 
Join Date: Mar 2005
Location: Where my hat is
Posts: 745
Hopefully he's taken the machine off line and will not put it back on line until it's fixed.

There's no sure fire way of knowing that you've cleaned up the machine. The only way to ensure that you have a clean machine is to wipe out the partitions, format the drives and reinstall the OS.
__________________
Registered Linux user #384279
retired1af is offline   Reply With Quote
Old 05-18-2005   #3 (permalink)
Linux User
 
Krendoshazin's Avatar
 
Join Date: Feb 2005
Location: London, England
Posts: 327
you can use a program called chkrootkit, you can get it here
http://freshmeat.net/redir/chkrootki...rootkit.tar.gz

it checks your binaries for rootkit modifications
http://web01.slackhost.net/~admin74/...chkrootkit.png
and then checks for the existance of any worms or rootkits
http://web01.slackhost.net/~admin74/...hkrootkit1.png

with that you can find out exactly what it is you have and act accordingly, it's also usefull to have for being proactive about security
__________________
"The search for the MOT JUSTE is not a pedantic fad but a vital necessity. Words are our precision tools. Imprecision engenders ambiguity and hours are wasted in removing verbal misunderstandings before the argument of substance can begin."

Do the things you use not respect you, the user? Then it's defective by design, so make your voice heard.
Krendoshazin is offline   Reply With Quote
Old 05-18-2005   #4 (permalink)
Just Joined!
 
Join Date: Feb 2004
Location: Indonesia
Posts: 84
this happened to me 1 months ago and this forum give some good information, but if you infected by suckit rootkit i have a link that maybe you can try it

http://www.soohrt.org/stuff/linux/suckit use rkhunter and combine it with chkrootkit, download the latest version.

similiar symtomps like ls, ps, netstat, pstree, find, locate is compromised binary

hope this help
kamtono is offline   Reply With Quote
Old 05-18-2005   #5 (permalink)
Linux Newbie
 
Join Date: Sep 2003
Location: St.Charles, Missouri, USA
Posts: 201
Send a message via AIM to gwalters Send a message via MSN to gwalters Send a message via Yahoo to gwalters
maybe for the gentoo users among us you could run (in a chroot) emerge world a few times and recompile everything.
__________________
Powered by Gentoo
never ever ever use the hardened option in make.conf!
gwalters is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Free Magazines
A Newbie's Getting Started Guide to Linux
Learn the basics of the Linux operating systems. Get to know what it is all about, and familiarize yourself with the practical side. Basically, if you're a complete Linux newbie and looking for a quick and easy guide to get you started this is it.
subscribe
Run Your Own Web Server Using Linux & Apache - Free 191 Page Preview
Learn about everything you'll need to build and maintain your Linux servers, and to deploy Web applications to them.
subscribe
Open Source Security Myths Dispelled
Dispel the five major myths surrounding Open Source Security and gain the tools necessary to make a truly informed decision for your IT organization
subscribe
InformationWeek
InformationWeek is the only newsweekly you'll need to stay on top of the latest developments in information technology.
subscribe



All times are GMT. The time now is 08:58 PM.






© 2000 - - All Rights Reserved - Property of  MAS Media

Content Relevant URLs by vBSEO 3.3.1