I spent a very unpleasant morning cleaning up a site after it got
breached.
The exploit occurred at 7:13 because access to the breached site was via a
firewall that deliberately logs TCP SYN packets. The attacked site was
running in.ftpd version wu-2.5.0(1) and I believe that was the entry
point. The logs show a source port 20 to unpriv destination port TCP SYN
packet at about 7:10, there is no matching port 21 activity. The attacker
created a directory /dev/tytt and dumped a tarball in there lrk.tar.
This was then unballed and setup.
The trojans that were compromised were: ls, ps, netstat, login, tcpd, sshd
and the ssh files including a set of site keys. I was alerted to it when
I logged onto the site with an alert about the site key having been
changed. I had previously been into the site the previous evening with no
problems.
It looks as if the trojan ls prog is not working properly, but the ps
certainly masked the running processes lpsched and x1xsnif (twice). The
site log showed that sshd was restarted at 7:13 and was running in
promiscuous mode on the local ethernet. These processes were sending out
icmp echo reply packets to two university sites in Europe but with no
incoming echo request packets. The port 20 attack came from a uni in the
UK, but I think the source might be a uni in Hungary, judging by the
signature on the ssh site keys.
I have not heard of any vulnerabilities in late version ftpd proggies, but
it seems that there is one.
If anyone wants further info then please contact me off list, similarly if
any one can offer constructive comment. Needless to say I have very
copious notes of everything I discovered.
Howard.
______________________________________________________
LANNet Computing Associates <http://www.lannet.com.au>
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text