Networking Forums

Networking Forums > Computer Networking > Linux Networking > Help.hacking?

Reply
Thread Tools Display Modes

Help.hacking?

 
 
happy
Guest
Posts: n/a

 
      04-14-2004, 06:49 PM
a large size of unknown traffic come from my machine udp port 32679
i found it is relate to my apache server because when i stop apache then
the traffic stop
and i found that a program /tmp/stealth is running own by apache user.
i tried to delete it and updated the apache and glibc but after i
started apache for a period of time.it happen again.is that got hacked?
any professional can help me.
thank you very much

 
Reply With Quote
 
 
 
 
happy
Guest
Posts: n/a

 
      04-14-2004, 06:52 PM
i am using redhat 7.3

happy wrote:

> a large size of unknown traffic come from my machine udp port 32679
> i found it is relate to my apache server because when i stop apache then
> the traffic stop
> and i found that a program /tmp/stealth is running own by apache user.
> i tried to delete it and updated the apache and glibc but after i
> started apache for a period of time.it happen again.is that got hacked?
> any professional can help me.
> thank you very much


 
Reply With Quote
 
Niels Basjes
Guest
Posts: n/a

 
      04-14-2004, 09:46 PM
On Thu, 15 Apr 2004 02:49:40 +0800, the lifeform known as happy
<(E-Mail Removed)> wrote:

>a large size of unknown traffic come from my machine udp port 32679
>i found it is relate to my apache server because when i stop apache then
>the traffic stop
>and i found that a program /tmp/stealth is running own by apache user.
>i tried to delete it and updated the apache and glibc but after i
>started apache for a period of time.it happen again.is that got hacked?
>any professional can help me.
>thank you very much


It sure sounds like it to me.
I suggest you check your system with one of the rootkit detection
scripts that are out there.
For example: http://www.rootkit.nl/


--
Niels.

Drs. ir. Niels Basjes - http://niels.basjes.nl/ - VCV 20000302
mailto:`echo 'Niels Basjes'|awk '{print$1"@"$2".nl"}'`
Hacker: One who enjoys the intellectual challenge of
creatively overcoming or circumventing limitations.
 
Reply With Quote
 
Dariusz =?iso-8859-2?Q?Kuli=F1ski?= / TaKeDa
Guest
Posts: n/a

 
      04-15-2004, 06:54 AM
On Thu, 15 Apr 2004 02:49:40 +0800, happy wrote:

> a large size of unknown traffic come from my machine udp port 32679
> i found it is relate to my apache server because when i stop apache then
> the traffic stop
> and i found that a program /tmp/stealth is running own by apache user.
> i tried to delete it and updated the apache and glibc but after i
> started apache for a period of time.it happen again.is that got hacked?
> any professional can help me.
> thank you very much


possibly it is some ddos program and somebody is using your computer to
attack others. You could (as Niels said) search for rootkits, and try to
remove them, but there could be something else that those tools wouldn't
detect. Also since somebody hacked to your computer probably can do it
again.

So my recommendation is to reinstall whole system, and patch it before
connecting to network. You should also keep current with updates.
No system is secure when admin isn't taking care of it, especially redhat,
which installs by default a lot of services that you don't really need
(more services = more ways to hack into your computer).
As a matter of a fact, I would recommend after installation to turn off
everything that you don't need or don't even use.

And again, keep your system current, patch ASAP as some security hole is
found.
--
(E-Mail Removed)t, ICQ# 15827691, GG# 113344, TLEN: taked4
EMAIL: (E-Mail Removed)
(remove CAPITAL letters from email if you want to contact me)
*http://eggdrop.takeda.tk - eggdrop & mods help*
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Router Hacking gargoyle60 Network Routers 0 11-14-2009 08:34 AM
'hacking' a Sky router /Tx2 Broadband 24 12-07-2007 08:00 AM
Hacking ideas? Turner Linux Networking 1 01-05-2007 12:56 AM
Hacking WEP wps Windows Networking 3 03-02-2005 12:42 PM
Hacking WEP wps Network Routers 4 02-25-2005 04:58 PM



1 2 3 4 5 6 7 8 9 10 11