Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    Member
    Join Date
    Oct 2002
    Posts
    35

    Default Server Compromised

    It appears that a RHEL3 server that I have got compromised a few hours ago - rkhunter returned the following:

    /bin/kill [ BAD ]
    /bin/login [ BAD ]
    /bin/dmesg [ BAD ]
    /sbin/depmod [ BAD ]
    /sbin/ifconfig [ BAD ]

    ......

    However, rkhunter and chkrootkit were unable to detect any rootkits on the server. Would it be safe to just replace these files with clean ones, or would it be better to do a complete reinstall?

    Any suggestions would be appreciated.

  2. #2
    Member
    Join Date
    Sep 2004
    Posts
    529

    Default

    Obviously you haven't been paying much attention to what's going on with your server... the reason that rkhunter is returning "BAD" for those programs is because the MD5 hashes have been changed (so the file has been changed), but the highly likely reason that the file has been changed is because up2date installed new versions from Redhat. RHEL3 is now at Taroon Update 4. So check that out first, there should be logs for up2date.

  3. #3
    Member
    Join Date
    Oct 2002
    Posts
    35

    Default

    Meh, guess I haven't been paying attention indeed
    I updated rkhunter, but I guess their MD5 hashes haven't been updated either?

    Thanks.

  4. #4
    Member
    Join Date
    Dec 2001
    Posts
    1,558

    Default

    You can keep trying to run rkhunter --update 2 maybe 3 times a day. I think the developer is probably busy with the holiday season and he's stated on the rkhunter web site it'll be a slow period at the moment.

    rkhunter is a great tool but it should not be the only tool you have to check this sort of stuff. When you first set up your server its a good idea to have a tool such as AIDE or perhaps Tripwire installed ( my pref = AIDE ). Installing these later on is somewhat useless, but if your certain your server is clean of any issues, it probably still a good idea.

    Best thing to do would be to consult an expert in this area to ensure you are as safe as possible.
    Beau Henderson

  5. #5
    Member
    Join Date
    May 2003
    Posts
    118

    Default

    Quote Originally Posted by iisnet
    It appears that a RHEL3 server that I have got compromised a few hours ago - rkhunter returned the following:

    /bin/kill [ BAD ]
    /bin/login [ BAD ]
    /bin/dmesg [ BAD ]
    /sbin/depmod [ BAD ]
    /sbin/ifconfig [ BAD ]

    ......

    However, rkhunter and chkrootkit were unable to detect any rootkits on the server. Would it be safe to just replace these files with clean ones, or would it be better to do a complete reinstall?

    Any suggestions would be appreciated.
    What is important is the whether these files are reported as clean when using rkhunter. The "bad" messages are due to these scripts being upgraded by up2date. You should have been notified of this via your /scripts/upcp report that you receive via e-mail.

    Brian

Similar Threads & Tags
Similar threads

  1. Server Compromised?
    By keykurt in forum New User Questions
    Replies: 2
    Last Post: 01-02-2007, 05:57 PM
  2. Server compromised or what?
    By mike_r in forum cPanel and WHM Discussions
    Replies: 18
    Last Post: 12-27-2004, 01:33 AM
  3. Compromised Server
    By mygregory in forum cPanel and WHM Discussions
    Replies: 9
    Last Post: 05-31-2004, 06:39 AM
  4. Our server was compromised
    By simonlee in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 10-23-2003, 07:20 PM
  5. My server is compromised?
    By avik in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 06-09-2003, 11:24 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube