Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
PostPosted: Sat Feb 03, 2007 1:28 am 
Offline
Senior Member

Joined: Sun Jul 20, 2003 8:29 am
Posts: 100
Website: http://www.ipo-australia.com
Location: Tropical Queensland, Australia
I went one one of my Mambo/php sites, instead of the usual stuff I found "HaCKeD By BeLa & BodyguarD (Turkish Hackers)". This is a PHP site and and I found a new index.html dated Jan 31.
It looks like they are very busy
http://www.google.com/search?q=bela+bodyguard
http://www.google.com/search?q=mambo+bela+bodyguard

This could be just a Mambo PHP hack (not so bad), or a full rookit (very bad). Suspecting a root kit, I installed chkrootkit & it shows:
Checking `lkm'... You have 57 process hidden for ps command
chkproc: Warning: Possible LKM Trojan installed

This does not sound good. I dont know if this is a false positive because of UML or a real rootkit. I have standard Redhat 9 running for 3 years, all passwords are mine an alpha-numeric, firehol is used as the firewall. I'm currently backing up everything using rsync.

So where do I go from here? I have no idea how this was done, they didn't seem to vandalise anything just show their presence. I suppose I will have to start again with a new distro and rebuild from scratch.


Top
   
 Post subject:
PostPosted: Sat Feb 03, 2007 2:04 am 
Offline
Senior Member
User avatar

Joined: Sun Feb 08, 2004 7:18 pm
Posts: 562
Location: Austin
Sounds bad. I'd wipe and start over, in your shoes. Not sure you can really trust anything on the system.

I've never seen a UML-caused chkrootkit false positive.


Top
   
 Post subject:
PostPosted: Mon Feb 05, 2007 1:56 am 
Offline
Junior Member

Joined: Tue Jan 25, 2005 10:45 pm
Posts: 33
Yep I run a few rootkit scanners when I do a server audit once in awhile I've never gotten a false positive regarding running processes.


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group