Re: cracked? "rm uses obsolete (PF_INET,SOCK_PACKET)"

2003-06-16 Thread Stefan Neufeind
On 15 Jun 2003 at 10:36, Noah Meyerhans wrote: > In terms of protecting against breakin, it seems like a lot of people > here have been advocating the grsecurity kernel patch. I have no > experience with it, but the list of features certainly makes it sound > like it will protect against some of

Re: cracked? "rm uses obsolete (PF_INET,SOCK_PACKET)"

2003-06-16 Thread Stefan Neufeind
On 15 Jun 2003 at 10:36, Noah Meyerhans wrote: > In terms of protecting against breakin, it seems like a lot of people > here have been advocating the grsecurity kernel patch. I have no > experience with it, but the list of features certainly makes it sound > like it will protect against some of

Re: cracked? "rm uses obsolete (PF_INET,SOCK_PACKET)"

2003-06-15 Thread [EMAIL PROTECTED]
Fuska schrieb: >>rm uses obsolete (PF_INET,SOCK_PACKET) >>... >>eth0: Setting promiscuous mode >>ppp0: Setting promiscuous mode >>... >> >>I found some stuff in /dev, hdx1 and hdx2 is that normal? >> > > > No, that isn't normal. It seems that you have been infected whith the rstb > virus.

Re: cracked? "rm uses obsolete (PF_INET,SOCK_PACKET)"

2003-06-15 Thread Rick Moen
Quoting Fuska ([EMAIL PROTECTED]): > No, that isn't normal. It seems that you have been infected whith the rstb > virus. It infects all executable files under /bin/ directory and under the > directory from which the infected file has been launched. Seach for > rstb_cleaner, whith this tool you can

Re: cracked? "rm uses obsolete (PF_INET,SOCK_PACKET)"

2003-06-15 Thread [EMAIL PROTECTED]
Fuska schrieb: >>rm uses obsolete (PF_INET,SOCK_PACKET) >>... >>eth0: Setting promiscuous mode >>ppp0: Setting promiscuous mode >>... >> >>I found some stuff in /dev, hdx1 and hdx2 is that normal? >> > > > No, that isn't normal. It seems that you have been infected whith the rstb > virus.

Re: cracked? "rm uses obsolete (PF_INET,SOCK_PACKET)"

2003-06-15 Thread Rick Moen
Quoting Fuska ([EMAIL PROTECTED]): > No, that isn't normal. It seems that you have been infected whith the rstb > virus. It infects all executable files under /bin/ directory and under the > directory from which the infected file has been launched. Seach for > rstb_cleaner, whith this tool you can

Re: cracked? "rm uses obsolete (PF_INET,SOCK_PACKET)"

2003-06-15 Thread Fuska
-BEGIN PGP SIGNED MESSAGE- On Saturday 14 June 2003 08:16, eyem wrote: > Hello, > Hello. > > rm uses obsolete (PF_INET,SOCK_PACKET) > ... > eth0: Setting promiscuous mode > ppp0: Setting promiscuous mode > ... > > I found some stuff in /dev, hdx1 and hdx2 is that normal? > No, t

Re: cracked? "rm uses obsolete (PF_INET,SOCK_PACKET)"

2003-06-15 Thread Fuska
-BEGIN PGP SIGNED MESSAGE- On Saturday 14 June 2003 08:16, eyem wrote: > Hello, > Hello. > > rm uses obsolete (PF_INET,SOCK_PACKET) > ... > eth0: Setting promiscuous mode > ppp0: Setting promiscuous mode > ... > > I found some stuff in /dev, hdx1 and hdx2 is that normal? > No, t

Re: cracked? "rm uses obsolete (PF_INET,SOCK_PACKET)"

2003-06-15 Thread Sebastian
Am Son, 2003-06-15 um 16.03 schrieb Phillip Hofmeister: > @daily apt-get -q -q -q -q update && apt-get -s -q -q -q -q upgrade Better use secpack, it will verify the signatures before upgrade: http://therapy.endorphin.org/secpack/ But still, automatic installation is not sufficient. For example,

Re: cracked? "rm uses obsolete (PF_INET,SOCK_PACKET)"

2003-06-15 Thread Noah Meyerhans
On Sun, Jun 15, 2003 at 04:29:36PM +0300, Mika Bostr?m wrote: > You must understand that Snort, ACID or any other IDS setup does not > provide any protection against threats. They just monitor what takes > place in the network. > > To really protect against break-ins, install a system monitor.

Re: cracked? "rm uses obsolete (PF_INET,SOCK_PACKET)"

2003-06-15 Thread Phillip Hofmeister
On Sun, 15 Jun 2003 at 04:13:19AM -0500, eyem wrote: > paranoid I now am!! > > I always found the concept of script kiddies amusing ... but if I ever found > this guy I'd ring his neck. Is there any way I can track him down ? (I have > already backed up some stuff and wiped my hard drive) You c

Re: cracked? "rm uses obsolete (PF_INET,SOCK_PACKET)"

2003-06-15 Thread Mika Boström
On Sun, 15 Jun 2003, eyem wrote: > > > Good luck... The only good thing about being compromised is that it > > makes you more paranoid about being on the net. > > paranoid I now am!! > > I always found the concept of script kiddies amusing ... but if I ever found > this guy I'd ring his neck.

Re: cracked? "rm uses obsolete (PF_INET,SOCK_PACKET)"

2003-06-15 Thread Sebastian
Am Son, 2003-06-15 um 16.03 schrieb Phillip Hofmeister: > @daily apt-get -q -q -q -q update && apt-get -s -q -q -q -q upgrade Better use secpack, it will verify the signatures before upgrade: http://therapy.endorphin.org/secpack/ But still, automatic installation is not sufficient. For example,

Re: cracked? "rm uses obsolete (PF_INET,SOCK_PACKET)"

2003-06-15 Thread Noah Meyerhans
On Sun, Jun 15, 2003 at 04:29:36PM +0300, Mika Bostr?m wrote: > You must understand that Snort, ACID or any other IDS setup does not > provide any protection against threats. They just monitor what takes > place in the network. > > To really protect against break-ins, install a system monitor.

Re: cracked? "rm uses obsolete (PF_INET,SOCK_PACKET)"

2003-06-15 Thread Phillip Hofmeister
On Sun, 15 Jun 2003 at 04:13:19AM -0500, eyem wrote: > paranoid I now am!! > > I always found the concept of script kiddies amusing ... but if I ever found > this guy I'd ring his neck. Is there any way I can track him down ? (I have > already backed up some stuff and wiped my hard drive) You c

Re: cracked? "rm uses obsolete (PF_INET,SOCK_PACKET)"

2003-06-15 Thread Mika Boström
On Sun, 15 Jun 2003, eyem wrote: > > > Good luck... The only good thing about being compromised is that it > > makes you more paranoid about being on the net. > > paranoid I now am!! > > I always found the concept of script kiddies amusing ... but if I ever found > this guy I'd ring his neck.

Re: cracked? "rm uses obsolete (PF_INET,SOCK_PACKET)"

2003-06-15 Thread eyem
> Good luck... The only good thing about being compromised is that it > makes you more paranoid about being on the net. paranoid I now am!! I always found the concept of script kiddies amusing ... but if I ever found this guy I'd ring his neck. Is there any way I can track him down ? (I have

Re: cracked? "rm uses obsolete (PF_INET,SOCK_PACKET)"

2003-06-15 Thread eyem
> Good luck... The only good thing about being compromised is that it > makes you more paranoid about being on the net. paranoid I now am!! I always found the concept of script kiddies amusing ... but if I ever found this guy I'd ring his neck. Is there any way I can track him down ? (I have

Re: cracked? "rm uses obsolete (PF_INET,SOCK_PACKET)"

2003-06-14 Thread Jamie Lawrence
On Sat, 14 Jun 2003, eyem wrote: > Hello, > > I think my box has been compromised.. its my first time and it is a > rather unpleasant experience! Yes, it sounds as if you have been, and yes, it is not fun. I sympathize (only happened to me once, which was more than enough). > I found som

Re: cracked? "rm uses obsolete (PF_INET,SOCK_PACKET)"

2003-06-14 Thread Jamie Lawrence
On Sat, 14 Jun 2003, eyem wrote: > Hello, > > I think my box has been compromised.. its my first time and it is a > rather unpleasant experience! Yes, it sounds as if you have been, and yes, it is not fun. I sympathize (only happened to me once, which was more than enough). > I found som

Re: cracked? "rm uses obsolete (PF_INET,SOCK_PACKET)"

2003-06-14 Thread David B Harris
On Sat, 14 Jun 2003 01:16:56 -0500 "eyem" <[EMAIL PROTECTED]> wrote: > Anyway, I have no idea where to go from here. > I dont know if it will be just a couple of things to fix up, or if I should > toast my whole system: major major hasstle) > > any help is appreciated Really, yes, you want to re

cracked? "rm uses obsolete (PF_INET,SOCK_PACKET)"

2003-06-14 Thread eyem
Hello, I think my box has been compromised.. its my first time and it is a rather unpleasant experience! debian woody on a p4 dell 8200 kernel 2.4.18 (that hasn't really been patched at all) I cant boot ... my system hangs on a message saying "starting portmap" I've used a gentoo ins

Re: cracked? "rm uses obsolete (PF_INET,SOCK_PACKET)"

2003-06-14 Thread David B Harris
On Sat, 14 Jun 2003 01:16:56 -0500 "eyem" <[EMAIL PROTECTED]> wrote: > Anyway, I have no idea where to go from here. > I dont know if it will be just a couple of things to fix up, or if I should > toast my whole system: major major hasstle) > > any help is appreciated Really, yes, you want to re

cracked? "rm uses obsolete (PF_INET,SOCK_PACKET)"

2003-06-13 Thread eyem
Hello, I think my box has been compromised.. its my first time and it is a rather unpleasant experience! debian woody on a p4 dell 8200 kernel 2.4.18 (that hasn't really been patched at all) I cant boot ... my system hangs on a message saying "starting portmap" I've used a gentoo ins