Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    Member
    Join Date
    Jul 2002
    Posts
    214

    Default Possible Slapper Warm found

    Hi there,

    After running today chkrootkit I have found in reports:
    "Checking `slapper'... Warning: Possible Slapper Worm installed "

    I have checked for the worm files within /tmp - did not find any... Also, I have followed remowal instruction provided here: http://bvlive01.iss.net/issEn/delive...sp?oid=21184.. Also, it did not help... Chrootkit still reports Slapper.

    I have also rebuild Apache and restarted box - did not help.

    Please help - any input will be appritiated.

    Regards,
    cretu

  2. #2
    Member
    Join Date
    Aug 2003
    Posts
    68

    Default Re: Possible Slapper Warm found

    I am no expert, but I will try to help. I have had this a couple of times.

    First, make sure you have the latest chkrootkit (0.43)

    Then run it, 2, 3, maybe 4 times in a row.

    Usually, this will make the warning go away.

    Then, run ./scripts/findtrojans

    This will make sure there was no trojans got installed with slapper.

    (This program will list several "posssible" trojans, but look for any suspecious files, there is topics in this forum that will tell you what to look for)

    I'm sure some of the pro's have some more ideas, but this has worked for me in the past.

    Also, make sure you patch your box to prevent this from happening again.

    Tim




    Originally posted by cretu
    Hi there,

    After running today chkrootkit I have found in reports:
    "Checking `slapper'... Warning: Possible Slapper Worm installed "

    I have checked for the worm files within /tmp - did not find any... Also, I have followed remowal instruction provided here: http://bvlive01.iss.net/issEn/delive...sp?oid=21184.. Also, it did not help... Chrootkit still reports Slapper.

    I have also rebuild Apache and restarted box - did not help.

    Please help - any input will be appritiated.

    Regards,
    cretu

  3. #3
    Member
    Join Date
    Jul 2002
    Posts
    214

    Default

    Hi there,

    I have managed to find out account of user who installed this worm so I have terminated him.

    However, I have found slapper again, on another box and also found the binary for it on account of user who is very trustwhorthy. Anyway, I have terminated him as well.

    Question: I have secured /tmp directory on each box making it non-executable, yet, still I could found out that last slapper was running from /tmp as "http" (file was actually called that). Also, I have php open_basedir Protection anabled...
    What other measure should I take against such attacks and possible worms?

    Regards,
    Cretu

  4. #4
    Member webolocity's Avatar
    Join Date
    Jul 2003
    Posts
    82

    Default Slapper

    How did you find the binary? How did you make sure the system was clean?

    Thanks

  5. #5
    Member webolocity's Avatar
    Join Date
    Jul 2003
    Posts
    82

    Default Slapper

    How did you find the binary? How did you make sure the system was clean?

    Thanks

Similar Threads & Tags
Similar threads

  1. Possible Slapper Worm?
    By xxkylexx in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 07-14-2006, 01:12 PM
  2. slapper worm installed?
    By Sheldon in forum cPanel and WHM Discussions
    Replies: 11
    Last Post: 08-19-2004, 07:36 PM
  3. Slapper worm attack!!!
    By atul in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 05-20-2004, 09:37 AM
  4. Linux SLAPPER Worm Virus
    By Drake in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 09-21-2002, 05:22 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube