My server was hacked.. :(

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • alex79
    Confirmed User
    • Jun 2002
    • 996

    #1

    My server was hacked.. :(

    They created a new user in mail group.. and installed a program called john from openwall.com locate at: ftp://dl.openwall.com:21/pvt/3d9a566...x-1.7.2.tar.gz
    i detected this becouse my server was slow.. when i checked the proces was around 10 "john" top rocesses runing..

    anybody know what is this program john they installed and runed on my server?

    i still don't know how they entered on my server.. if they created a new user then they had root access or the user can be created under other user?

    i've deleted the new user they created, changed the root and ftp password..what should i do next?
  • alex79
    Confirmed User
    • Jun 2002
    • 996

    #2
    no advice?

    Comment

    • WarChild
      Let slip the dogs of war.
      • Jan 2003
      • 17263

      #3
      Originally posted by alex79
      what should i do next?
      Being as you're location is France, maybe try doing what the Fench do best and simply surrender?
      .

      Comment

      • kaori
        Confirmed User
        • Apr 2005
        • 1569

        #4
        wonder in John is a brute force password cracker??? john the ripper

        Comment

        • k0nr4d
          Confirmed User
          • Aug 2006
          • 9231

          #5
          Originally posted by WarChild
          Being as you're location is France, maybe try doing what the Fench do best and simply surrender?
          best reply ever.
          Mechanical Bunny Media
          Mechbunny Tube Script | Mechbunny Webcam Aggregator Script | Custom Web Development

          Comment

          • Altheon
            Confirmed User
            • May 2004
            • 506

            #6
            Since you don't know how they got in you are looking at a pretty ugly situation. First I would check to see if you are running any old scripts like an outdated version of PhpBB. Often those are ways your typical script kiddie gets in.

            When you do find the hole, patch it and move on. If they were in there as root, then just pony up the money for an OS reinstall and put your backup on then fix the security leak.

            -A

            Comment

            • Vlad
              Confirmed User
              • Dec 2002
              • 2864

              #7
              you better contact your server admin asap !

              Comment

              • LukieD
                Confirmed User
                • Dec 2001
                • 927

                #8
                yup it's a password cracker. More info here: http://www.openwall.com/john/pro/

                If I were you and you aren't experienced in server security I'd get a professional to look at your server. Pay your host to secure it.

                Comment

                • alex79
                  Confirmed User
                  • Jun 2002
                  • 996

                  #9
                  Originally posted by kaori
                  wonder in John is a brute force password cracker??? john the ripper
                  yeah..is john the ripper.. but since they cold create a new user i asume that they got already the password in order to create this user.. why wold they need a brute force password cracker anymore then?

                  Comment

                  • Ray@TastyDollars
                    • May 2002
                    • 6797

                    #10
                    Where are you hosted and have you contacted them about this?

                    Ray

                    Comment

                    • pr0
                      rockin tha trailerpark
                      • May 2001
                      • 23088

                      #11
                      Originally posted by WarChild
                      Being as you're location is France, maybe try doing what the Fench do best and simply surrender?
                      dude i'm crying
                      __________
                      Loadedca$h - get sum! - Revengebucks - mmm rebills! - webair (gotz sErVrz)

                      Comment

                      • Jarmusch
                         
                        • May 2003
                        • 12479

                        #12
                        Originally posted by WarChild
                        Being as you're location is France, maybe try doing what the Fench do best and simply surrender?

                        Comment

                        • fuzebox
                          making it rain
                          • Oct 2003
                          • 22363

                          #13
                          Originally posted by alex79
                          yeah..is john the ripper.. but since they cold create a new user i asume that they got already the password in order to create this user.. why wold they need a brute force password cracker anymore then?
                          Oh man john is sooo old school, takes me back

                          The answer is, for when you patch whatever vulnerable daemon gave them shell access in the first place, they can simply login as a normal user (on a multiuser box most people won't change those passwords after a compromise) and run whatever rootshell they left planted around your system.

                          Box is fucked, get a new one and copy your sites over.

                          Comment

                          • NemesiS876
                            Confirmed User
                            • May 2006
                            • 7436

                            #14
                            try to find him, then slay him and at the end sue him

                            Comment

                            • aico
                              Moo Moo Cow
                              • Mar 2004
                              • 14748

                              #15
                              Originally posted by WarChild
                              Being as you're location is France, maybe try doing what the Fench do best and simply surrender?

                              Comment

                              • chaze
                                Confirmed User
                                • Aug 2002
                                • 9774

                                #16
                                Run a root check:

                                To install chrootkit, SSH into server and login as root.

                                At command prompt type: cd /root/

                                At command prompt type: wget ftp://ftp.pangeia.com.br/pub/seg/pac/chkrootkit.tar.gz

                                At command prompt type: tar xvzf chkrootkit.tar.gz

                                At command prompt type: cd chkrootkit-0.47

                                At command prompt type: make sense


                                To run chkrootkit

                                At command prompt type: /root/chkrootkit-0.47/chkrootkit

                                If you clean then remove the account on the server and start it over. Any page can be a back door so really you should start it over.
                                Like the desert needs the rain
                                We do fully manged WordPress, VPS, and Servers. Adult Host Pro https://adulthostpro.com/ Since 2001

                                Comment

                                Working...