Re: Server hacked?



On 01/01/2008 02:00 PM, Joris Dobbelsteen wrote:


The box has PostFix, PowerDNS, Apache2 and SSH exposed to the Internet.
Unfortunally its connected to the single LAN segment I have at home.
Fortunally I have a strict firewall that doesn't allow IRC out (I don't
use it, so I do not need to allow it).

[snips]
tcp 0 1 192.168.10.xx:60278 216.152.66.47:6667
SYN_SENT 15412/[kjournald]
[trusted entries removed]



You have been hacked. There are a variety of trojans (linx related) that
use port 6667:

http://www.cert.org/advisories/CA-2002-24.html
<http://www.google.com/search?hl=en&q=Linux+trojan+%2B6667&btnG=Search>
<http://www.symantec.com/security_response/writeup.jsp?docid=2006-021417-0144-99&tabid=2>
<http://www.doshelp.com/Ports/6667.htm>

Is the system fully updated with all the recent Ubuntu patches/updates?
If so, you may want to contact the Ubuntu security team to let them know
and have them take a look.
https://launchpad.net/~ubuntu-security
https://bugs.launchpad.net/~ubuntu-security/
https://bugs.launchpad.net/debian/+source/ircii-pana/+bug/129771
[remote IRC servers can execute arbitrary commands]








--
ubuntu-users mailing list
ubuntu-users@xxxxxxxxxxxxxxxx
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-users



Relevant Pages

  • Re: Homa - Ubuntu Addon CD
    ... I have plenty of disk and my internet is 4mb down ... install more than 60 packages on your installed Ubuntu. ... Homa will install these packages now, ... VLC Multimedia Player ...
    (Ubuntu)
  • Re: Very slow network - Ubuntu
    ... slowed down considerably since I installed Ubuntu Dapper I ... Win2k KIDPC on the same home network that do not have ... internet connection and you are using at least 100Mb ethernet (i.e.the ... connection speed is only 1Mbps My internet download speeds range ...
    (Debian-User)
  • Re: OT: Linux Question
    ... You are going to need a modem.Most ISP (Internet service provider) ... Consider getting a new computer with Ubuntu, ... that it is more stable then windows and all the sosftware is freeware ... I am a long time poster on this newsgroup and I always preface my subject line ...
    (rec.gambling.poker)
  • Re: OT: Linux Question
    ... You are going to need a modem.Most ISP (Internet service provider) ... Consider getting a new computer with Ubuntu, ... that it is more stable then windows and all the sosftware is freeware ... I am a long time poster on this newsgroup and I always preface my ...
    (rec.gambling.poker)
  • Re: repair win xp
    ... My incomplete GRUB was the result of a failed Ubuntu installation. ... (incl historical WIN, incl NTFS) ... It gives Internet access and has a browser. ...
    (Ubuntu)