Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  This topic is locked, you cannot edit posts or make further replies.
Author Message
 Post subject: Hacked
PostPosted: Mon Jun 26, 2006 8:51 am 
Offline
Senior Newbie

Joined: Mon Jan 30, 2006 12:54 am
Posts: 15
My linode, now offline, was responsible for this report:

http://www.mynetwatchman.com/ListIncide ... =206738902

Can anyone throw any light on what sort of weakness was exploited to enable this intrusion, and what I might do to prevent a repeat performance when I reinstall my linode?

tia,

_________________
Dean Swift


Top
   
 
 Post subject: Re: Hacked
PostPosted: Mon Jun 26, 2006 9:26 am 
Offline
Senior Newbie

Joined: Mon Jan 30, 2006 12:54 am
Posts: 15
Is it me, or doesn't this look AN AWFUL LOT like an nmap scan?

deanswift wrote:

_________________
Dean Swift


Top
   
 
 Post subject: Re: Hacked
PostPosted: Mon Jun 26, 2006 9:35 am 
Offline
Senior Newbie

Joined: Mon Jan 30, 2006 12:54 am
Posts: 15
deanswift wrote:
Is it me, or doesn't this look AN AWFUL LOT like an nmap scan?


Look at the report's fine print. All of these agents are Windows creatures; none of these afaik can live on a linux host. Am I wrong?

"Since the target port includes udp/137 (NetBios Adapter Status), then this host is likely infected with the OpaServ worm.
See: http://www.mynetwatchman.com/kb/securit ... 17/137.htm

"Since the target port includes tcp/445 (Microsoft CIFS), then this
host is likely infected with the Sasser or Agobot worm.
See: http://www.mynetwatchman.com/kb/securit ... /6/445.htm

"Since the target port includes tcp/135 (Microsoft RPC), then this
host is likely infected with the MSBlast / Lovsan worm.
See: http://www.mynetwatchman.com/kb/securit ... /6/135.htm

I *did* run nmap scans -- with permission of a responsible party at the target host -- a couple of days this month. And, the scans were of a host in the northwestern part of the country, where he.net lives.

_________________
Dean Swift


Top
   
 
 Post subject: Re: Hacked
PostPosted: Mon Jun 26, 2006 9:54 am 
Offline
Senior Newbie

Joined: Mon Jan 30, 2006 12:54 am
Posts: 15
deanswift wrote:
I *did* run nmap scans -- with permission of a responsible party at the target host -- a couple of days this month. And, the scans were of a host in the northwestern part of the country, where he.net lives.


No good deed goes unpunished. I just checked the IP address I scanned WITH PERMISSION against that myNetWatcher report. The first two numbers, 69.1.x.x, are a match. I think that clinches it. I am hoist on my own petard!

Case closed. Sorry to make such a fuss.

_________________
Dean Swift


Top
   
 
 Post subject: Re: Hacked
PostPosted: Wed Jun 28, 2006 4:20 pm 
Offline
Linode Staff
User avatar

Joined: Fri Oct 17, 2003 12:38 am
Posts: 287
Location: Dr Wierd's Lab, South Jersey Shore
deanswift wrote:
Look at the report's fine print. All of these agents are Windows creatures; none of these afaik can live on a linux host. Am I wrong?

"Since the target port includes udp/137 (NetBios Adapter Status), then this host is likely infected with the OpaServ worm.
See: http://www.mynetwatchman.com/kb/securit ... 17/137.htm

"Since the target port includes tcp/445 (Microsoft CIFS), then this
host is likely infected with the Sasser or Agobot worm.
See: http://www.mynetwatchman.com/kb/securit ... /6/445.htm

"Since the target port includes tcp/135 (Microsoft RPC), then this
host is likely infected with the MSBlast / Lovsan worm.
See: http://www.mynetwatchman.com/kb/securit ... /6/135.htm

I *did* run nmap scans -- with permission of a responsible party at the target host -- a couple of days this month. And, the scans were of a host in the northwestern part of the country, where he.net lives.


They don't say that the system is infected with these worms, they just say that it is likely, which is true.

Since the sys/networkadmin at the target ip that you nmapped took the time to report your activity, you obviously didn't have permission from somebody that was in a position to grant that permission to you.


Top
   
 
Display posts from previous:  Sort by  
Post new topic  This topic is locked, you cannot edit posts or make further replies.


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group