Welcome to Linux Forums! With a comprehensive Linux Forum, information on various types of Linux software and many Linux Reviews articles, we have all the knowledge you need a click away, or accessible via our knowledgeable members.
Write an article for LinuxForums Today!
Try Our New Product Showcase!
Find the answer to your Linux question:
New to Linux Forums? Register here for free!
    Linux Forums > GNU Linux Zone > Linux Security > SHV4, SHV5 Rootkit Installed

Forgot Password?
 Linux Security   Discussion about keeping your machines secure, and the crackers out.

Site Navigation
Linux Forums
Linux Articles
Product Showcase
Linux Downloads
Linux Hosting
Free Magazines
Job Board
IRC Chat
RSS Feeds
Free Publications




Linux Forum Topics
Linux Forums
Your Distro
Linux Resources
GNU Linux Zone
The Community
Reply
 
Thread Tools Display Modes
Old 10-22-2005   #1 (permalink)
Just Joined!
 
Join Date: Oct 2005
Posts: 3
Send a message via Yahoo to ServerSurgeon
SHV4, SHV5 Rootkit Installed

A customer of mine called me today and told me he thought his Linux FC 2 system was hacked. His dedicated server provider informed him of DOS attacks originating from his machine going outbound to ports 53 and 6667 to varied IPs. Investigation revealed the server was compromised nearly two weeks ago. When I got on the box I ran top and ps, both of which gave me this odd output:

Unknown HZ value! (75) Assume 100.

Running rkhunter revealed that rootkits SHV4 and SHV5 had most likely been installed. Further investigation revealed the following files to have been modified or installed by the hacker:

/lib/libsh.so/shrs
/lib/libsh.so/shhk
/lib/libsh.so/shhk.pub
/sbin/ttymon
/sbin/ttyload
/sbin/ifconfig
/usr/lib/libsh/.sniff/shp
/usr/lib/libsh/.sniff/shsniff
/usr/lib/libsh/.bashrc
/usr/lib/libsh/shsb
/usr/lib/libsh/hide
/usr/sbin/lsof
/usr/bin/pstree
/usr/bin/find
/usr/bin/top
/usr/bin/dir
/usr/bin/slocate
/usr/bin/md5sum
/bin/ps
/bin/ls
/bin/netstat
/var/tmp/httpd

The files cannot be removed in any way. I've even tried copying unlink from an unaffected host but with no luck.

[root@XXXXXX]# ls -l /bin/ps
-rwxr-xr-x 1 122 114 62920 Jan 27 2005 /bin/ps
[root@XXXXXX]# /tmp/unlink /bin/ps
/tmp/unlink: cannot unlink `/bin/ps': Operation not permitted
[root@XXXXXX ]# chown root /bin/ps
chown: changing ownership of `/bin/ps': Operation not permitted

Adding a user to the system with UID 122 and trying to perform operations as that user avails nothing either. Perhaps someone here will know how to remove the files from the inode level. (We are going to re-image the server so we don't really need to delete the files, but as a Linux administrator it's very frustrating when you can delete a file as the root user). Or perhaps someone has had a similiar experience. Or perhaps the perpetrator will pick this up in a google search and get (in whatever weird, perverted way) the satisfaction he so desperately needs.
ServerSurgeon is offline  



Reply With Quote
Old 11-04-2005   #2 (permalink)
Just Joined!
 
Join Date: Nov 2005
Location: EPA, California
Posts: 1
Looks like the attributes have be changed

The command chattr can be used to change the fundamental attributes of the file. The attribut that has probably been set by the hacker is the immutable attribute, this will prevent the file from being deleted or moved.

Check out the man pages on chattr

This discussion group has a post describing how to scrub a system.
http://www.derkeiler.com/Mailing-Lis...1-10/0078.html

Personally, I would do what you are doing and just wipe the system clean.

By the way, how did you determine when the initial intrusion took place?
Asticamper is offline   Reply With Quote
Old 11-04-2005   #3 (permalink)
Linux Guru
 
anomie's Avatar
 
Join Date: Mar 2005
Location: Texas
Posts: 1,696
Quote:
Personally, I would do what you are doing and just wipe the system clean.
I will second that. And get the rebuilt system up to date - I am not sure how the FC releases work exactly, but don't they have a newer "stable" version than FC2 by now?

You also might consider creating an image / backup of the compromised system. This will let you:
* Study it to try to determine how the compromise occurred.
* Determine whether important data may have been stolen or altered.
* Maintain evidence for potentially pressing charges.

If you do not back it up before wiping it clean you lose evidence and may or may not learn anything from the compromise.
anomie is offline   Reply With Quote
Old 11-04-2005   #4 (permalink)
/etc/init.d/moderator
 
bigtomrodney's Avatar
 
Join Date: Nov 2004
Location: Sunny South-East of Ireland
Posts: 6,104
I also support getting a new system up and running, but I would have to say if you need to modify these files try doing it with a live disc, where the system will be offline and you can work more easily.

Probably better that you rebuild, though kudos on locating the modified files.
__________________
Registered Linux user #378740
New members read here / Forum Rules
#linuxforums on irc.freenode.net
bigtomrodney is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Free Magazines
Implementing Detailed User-Level Auditing of UNIX & Linux Systems
Enhance regulatory compliance and troubleshooting through detailed auditing, logging and real-time monitoring of UNIX/Linux user activity.
subscribe
Linux from Scratch - Receive Your Complimentary eBook NOW!
Linux from Scratch describes the process of creating your own Linux system from scratch from an already installed Linux distribution, using nothing but the source code of software that you need.
subscribe
A Complete Beginner's Manual for Ubuntu 10.04 (Lucid Lynx)
Getting Started with Ubuntu 10.04 (Lucid Lynx) is a comprehensive beginners guide for the Ubuntu operating system; it features comprehensive guides, How Tos and information on anything you need to know after first installing Ubuntu.
subscribe
The Incredible Guide to NEW Ubuntu (Karmic Koala)
There are a lot of people still stuck with Windows because it's the ‘easier alternative'. Linux is both cheaper and more versatile than Microsoft's operating system, but the learning curve has frightened off many people.
subscribe
The GNU/Linux Advanced Administration
The GNU/Linux systems have reached an important level of maturity, allowing to integrate them in almost any kind of work environment, from a desktop PC to the sever facilities of a big company.
subscribe
A Newbie's Getting Started Guide to Linux
Learn the basics of the Linux operating systems. Get to know what it is all about, and familiarize yourself with the practical side. Basically, if you're a complete Linux newbie and looking for a quick and easy guide to get you started this is it.
subscribe
Run Your Own Web Server Using Linux & Apache - Free 191 Page Preview
Learn about everything you'll need to build and maintain your Linux servers, and to deploy Web applications to them.
subscribe



All times are GMT. The time now is 01:18 AM.






© 2000 - - All Rights Reserved - Property of  MAS Media

Content Relevant URLs by vBSEO 3.3.1