To subscribe or unsubscribe via the World Wide Web, visit
http://lists.freebsd.org/mailman/listinfo/freebsd-security
or, via email, send a message with subject or body 'help' to
freebsd-secu...@freebsd.org
You can reach the person managing the list at
freebsd-sec...@freebsd.org
When replying, please edit your Subject line so it is more specific
than "Re: Contents of freebsd-security digest..."
Today's Topics:
1. Hacked or not appendice (Peter Rosa)
2. Re: Hacked or not ? (Lupe Christoph)
3. Re: Hacked or not ? (jon.m...@achean.com)
4. Re: Hacked or not ? (Peter Rosa)
5. Re: Hacked or not appendice (Thordur Ivar)
6. Re: Hacked or not appendice (Alex Povolotsky)
7. Re: Hacked or not ? (Alex Povolotsky)
8. How do I tell I was hacked? (richard childers / kg6hac)
9. Re: Hacked or not appendice (Lupe Christoph)
10. Re: Hacked or not appendice (Peter Jeremy)
11. Re: [Freebsd-security] Re: Hacked or not appendice (Remko Lodder)
12. Re: Hacked or not - RESULT (Peter Rosa)
13. FYI: new port security/portaudit-db (Oliver Eikemeier)
----------------------------------------------------------------------
Message: 1
Date: Sat, 12 Jun 2004 13:44:45 +0200
From: "Peter Rosa" <pr...@pro.sk>
Subject: Hacked or not appendice
To: "FreeBSD Security" <freebsd-...@freebsd.org>
Message-ID: <019101c45072$a8b9cfe0$3501...@pro.sk>
Hi all again,
I must add, there are no log entries after June 9, 2004. "LKM" message first
apeared June 8, 2004, after this day, there is nothing in /var/messages,
/var/security .....
How could I look for suspicious LKM module ? How could I find it, if the
machine is hacked and I can not believe "ls", "find" etc. commands ?
Peter Rosa
------------------------------
Message: 2
Date: Sat, 12 Jun 2004 13:47:00 +0200
From: lu...@lupe-christoph.de (Lupe Christoph)
Subject: Re: Hacked or not ?
To: Peter Rosa <pr...@pro.sk>
Cc: FreeBSD Security <freebsd-...@freebsd.org>
Message-ID: <2004061211...@lupe-christoph.de>
Content-Type: text/plain; charset=us-ascii
On Saturday, 2004-06-12 at 13:15:33 +0200, Peter Rosa wrote:
> please advice me - I was on holidays for one week. After return I found in
> security mails from router (chkrootkit) following message:
> Checking `lkm'... You have 1 process hidden for readdir command
> You have 1 process hidden for ps command
> Warning: Possible LKM Trojan installed
> It apeared only onece. From previous and next days reports, the message is
> not present.
This is an artifact. chkrootkit uses two methods to look at the running
processes - ps and /proc. When a process terminates between the two
runs, you will get this. I see it at irregular intervals on all my
machines that run chkrootkit.
But if your machine is critical, running chkrootkit once daily is not
enough. This gives a cracker too much time to nest in. Run it at least
every hour.
Are you running an integrity checker like AIDE, Tripwire, etc?
> How could I be sure, the machine is not hacked ?
You can't. Not in general. chkrootkit goes only so far. Always assume
the worst. But don't panick.
HTH,
Lupe Christoph
PS: Flames that this is not a security help mailing list to /dev/null,
please. If you want to flame me, put the energy into creating a
freebsd-security-help mailing list instead.
--
| lu...@lupe-christoph.de | http://www.lupe-christoph.de/ |
| "... putting a mail server on the Internet without filtering is like |
| covering yourself with barbecue sauce and breaking into the Charity |
| Home for Badgers with Rabies. Michael Lucas |
------------------------------
Message: 3
Date: Sat, 12 Jun 2004 13:01:38 +0100 (BST)
From: jon.m...@achean.com
Subject: Re: Hacked or not ?
To: freebsd-...@freebsd.org
Message-ID:
<55017.217.155.191.90...@webmail.achean.com>
Content-Type: text/plain;charset=iso-8859-1
I have seen this as well, it is most likely a false positive.
Additionally, slower or more heavily loaded machines seem more likely to
generate false positive for LKM.
As a side note, there really ought to be a way for admins to double check
the output from chkrootkit Google helps little. Any offers..?
Jon
> Hi all,
>
> please advice me - I was on holidays for one week. After return I found
in security mails from router (chkrootkit) following message:
> Checking `lkm'... You have 1 process hidden for readdir command You
have 1 process hidden for ps command
> Warning: Possible LKM Trojan installed
>
> It apeared only onece. From previous and next days reports, the message
is not present.
>
> How could I be sure, the machine is not hacked ?
>
> Many thanks for any response.
>
> Peter Rosa
>
>
> _______________________________________________
> freebsd-...@freebsd.org mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-security
> To unsubscribe, send any mail to
> "freebsd-securi...@freebsd.org"
>
------------------------------
Message: 4
Date: Sat, 12 Jun 2004 14:39:21 +0200
From: "Peter Rosa" <pr...@pro.sk>
Subject: Re: Hacked or not ?
To: "Lupe Christoph" <lu...@lupe-christoph.de>
Cc: FreeBSD Security <freebsd-...@freebsd.org>
Message-ID: <01b701c4507a$49399840$3501...@pro.sk>
Yes, it runs Tripwire. There is nothing unusual in it's logs.
I wanted to have some sureness. That message NEVER apeared on that machine
before and chkrootkit is running about one year. In the same time I found
some trojans originating from web sites on another Windoze machine on my
network. So I got scared if my router couldn't be hacked.
May be, the "LKM" message was done because of some process terminated as you
wrote. It's also used as a mailserver with AV daemons, so there are such
"temporary" processes.
But what about the /var/log/messages logs absence ?
And, how to test the machine, if it is healthy ?
Peter Rosa
P.S Sorry, if this is not the PROPER list, but I'm a member of few another
lists and this one seems as proper as possible for me. It's about SECURITY,
isn't it ?
------------------------------
Message: 5
Date: Sat, 12 Jun 2004 13:03:07 +0000
From: Thordur Ivar <th...@mi.is>
Subject: Re: Hacked or not appendice
To: freebsd-...@freebsd.org
Message-ID: <20040612130307...@mi.is>
Content-Type: text/plain; charset=US-ASCII
I have on a CD a number of binarys ( sources actually ) ( e.g. ls, find, grep, awk, sed, locate e.t.c. ) and when I belive that a machine has been cracked I remove the network cable from that machine and mount the cdrom build the sources and start looking. If I need something in that process I put it on my USB memstick from a 'trusted machine' and move it by hand over.
Roughly speaking this is my process.
>On Sat, 12 Jun 2004 13:44:45 +0200
>"Peter Rosa" <pr...@pro.sk> wrote:
> Hi all again,
>
> I must add, there are no log entries after June 9, 2004. "LKM" message first
> apeared June 8, 2004, after this day, there is nothing in /var/messages,
> /var/security .....
>
> How could I look for suspicious LKM module ? How could I find it, if the
> machine is hacked and I can not believe "ls", "find" etc. commands ?
>
> Peter Rosa
>
>
> _______________________________________________
> freebsd-...@freebsd.org mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-security
> To unsubscribe, send any mail to "freebsd-securi...@freebsd.org"
>
>
------------------------------
Message: 6
Date: Sat, 12 Jun 2004 17:45:29 +0400
From: Alex Povolotsky <tar...@webmail.sub.ru>
Subject: Re: Hacked or not appendice
To: freebsd-...@freebsd.org
Message-ID: <20040612174...@tarkhil.over.ru>
Content-Type: text/plain; charset=US-ASCII
On Sat, 12 Jun 2004 13:03:07 +0000
Thordur Ivar <th...@mi.is> wrote:
TI> I have on a CD a number of binarys ( sources actually ) ( e.g. ls,
TI> find, grep, awk, sed, locate e.t.c. ) and when I belive that a
TI> machine has been cracked I remove the network cable from that
TI> machine and mount the cdrom build the sources and start looking. If
TI> I need something in that process I put it on my USB memstick from a
TI> 'trusted machine' and move it by hand over.
When I was unable to do the same thing, I've recompiled md5 tool from freshly fetched sources and used it to test utilities. I don't beleive in attacker catching thr build process transparently...
--
Alex.
------------------------------
Message: 7
Date: Sat, 12 Jun 2004 17:50:35 +0400
From: Alex Povolotsky <tar...@webmail.sub.ru>
Subject: Re: Hacked or not ?
To: freebsd-...@freebsd.org
Message-ID: <20040612175...@tarkhil.over.ru>
Content-Type: text/plain; charset=US-ASCII
On Sat, 12 Jun 2004 14:39:21 +0200
"Peter Rosa" <pr...@pro.sk> wrote:
PR> But what about the /var/log/messages logs absence ?
PR> And, how to test the machine, if it is healthy ?
Boot from CD and compare md5 checksums on system files. That's the first step.
Compare your kernel sources with clean ones, rebuild kernel and compare it with the running one. If you're running GENERIC, compare it with the distributed one.
Compare /modules directory with distribution one.
Check your (and system) .profile or .login etc.
After this step, you should have reasonably clean system.
--
Alex.
------------------------------
Message: 8
Date: Sat, 12 Jun 2004 07:04:54 -0700
From: richard childers / kg6hac <fsc...@pacbell.net>
Subject: How do I tell I was hacked?
To: freebsd-...@freebsd.org
Message-ID: <40CB0D86...@pacbell.net>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
>
>
>Date: Sat, 12 Jun 2004 13:15:33 +0200
>From: "Peter Rosa" <pr...@pro.sk>
>Subject: Hacked or not ?
>To: "FreeBSD Security" <freebsd-...@freebsd.org>
>Message-ID: <016301c4506e$947644e0$3501...@pro.sk>
>
>Hi all,
>
>please advice me - I was on holidays for one week. After return I found in
>security mails from router (chkrootkit) following message:
>Checking `lkm'... You have 1 process hidden for readdir command
>You have 1 process hidden for ps command
>Warning: Possible LKM Trojan installed
>
>It apeared only onece. From previous and next days reports, the message is
>not present.
>
>How could I be sure, the machine is not hacked ?
>
>
[1] Make backups. tar(1), dump(8), doesn't matter.
[2] Reinstall identical operating system on new equipment.
[3] Restore backups into large partition sized for this operation
(call it '/backups').
[4] Compare the contents of each directory in /backups recursively
against a known
good copy, For example, to compare /usr against the backed-up
image, do this:
# diff -r /usr /backups/usr
[5] Review the list for files which differ or which do not exist on
the known good copy.
[6] Exclude files for which there are good reasons for difference (IE,
logs and state files).
[7] Analyze the resulting files; pay particular attention to
executables, but also libraries.
You may also find it useful to reload the old operating system onto a
box on an insulated network and monitor the operating system, its
processes and its network traffic, using known good tools.
Regards,
-- richard
--
Richard Childers / Senior Engineer
Daemonized Networking Services
945 Taraval Street, #105
San Francisco, CA 94116 USA
[011.]1.415.759.5571
http://www.daemonized.com
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v1.2.4 (FreeBSD)
mQGiBECGpfsRBACoPJJfIIrWAqjlW92TtYCtY//e7OW8alWylr/1ygtSQzjCCdvC
Ysa0fCcx01UenlWV+5YY/zC7KPsX2rQUKAs20fqs9et74dmgMGOj0vMjTzWEs29G
FyAsIRSpFioa8zzrjXEUVnU6OFaD9a9eaC+LSTCiKgXjbQySDKM5T1c+vwCg8W3Y
RZ83LRIUULGMPlY6zS4fQwUEAIIiTHDdWpbE+HeREJwH+4eDpGVf76XtNlOMXrt9
tJ3ExL+9ezLulg1nCrOYodOB7TEZqzV40R7emDZSX0hI9QEBCv6nW5aDVpw/bf+q
UEHwxrUvE2LBi35hoqR2QwqNlagOauSorWj8Qm/31luxJVeLVy1A1czp6B/mvG1T
co03A/9a5kzEAebJ5TzWXQC2/4gu/osXQnrw9B9FFpYOtLc0MNQuAFt8VLn5yO5Q
8T58w+FQvFI5FqzI5URmjQeEyWWuyIechknk4RnwIO1UPVjgRTuNgf9/TvNNfqpa
aVlbNp+AG21D6VqsFN2zJFFJeUqiYdXw6i+ESL3SZRymIhwYWrQ8UmljaGFyZCBB
IENoaWxkZXJzICh3d3cuZGFlbW9uaXplZC5jb20pIDxmc2NrZWRAcGFjYmVsbC5u
ZXQ+iF4EExECAB4FAkCGpfsCGwMGCwkIBwMCAxUCAwMWAgECHgECF4AACgkQjGqW
TlNTP66KzQCgjf0SQbiK1rgu7hRsmLPSSaGF7X8AoL7Qw/E9kTZr0fntP0XXEnk/
q6nRuQINBECGpvkQCADFzFq+kYbk+KTIhcVBTjTWDbBnjGgmuGR3LGp9hOd6W9SJ
i4GD5184ZnMbEgvDZcDEGDNgMcU+f1girwYI2v/o7QA7VQ5bpUbnfOBytzO+bvd7
uCOyJltg8AG5MFLxfhAMHofpNxGlFTEXdVp4M9xyBB+hdLHbJNJqkMGPf+iCUf1W
Q86KncU2AK4Sf9I+WYBZwkjaIhi9dQzeEX1c0Um6LxXSBtkjZprIk1M13gVaIJ6E
dDN6hrSMbXZL+7yURw38vHXCtRJAKEOyW178rI8MzJzvVNhobvC62uEWD9Idz8sH
5A06fqb2fKJYLQ1keGUpb/qpny7oTmAe0Hx9jOM7AAMGCACdTe1M4U++/7/OVGip
1gnWEtMhHeQQbS7KPh1w8/1kvs5Mml6uGYQI44lKTDP7OHJQ9hIT/+5tfKPHIPhU
M/7Mqa8y81c/AK+WUOyY9+uZ0zUxFGMqeU9z5iqJFWSi9QR/f5q/khfmqi5RFVyQ
nnVhxBMB8pY1vZHV1CoL7NLK4c/N8mpwCiZ57LTsP8pLfDMWF/OopmM2ulzlfWTr
anAdxQohenq/zTgSySX/VGZYSYvyAoXTRuU4USAVGWcUQPnVooA1N7lZP3pawjNP
QMSukx9jI1673BPsPXxyQZ1PmmPt9eHKI0G0hNJG+FCmSRLNT/R7hqTzTUmpgMWM
yyWPiEkEGBECAAkFAkCGpvkCGwwACgkQjGqWTlNTP642KACeITHq0b42P3oMX7Nj
F5U3EaqCgYoAn3HxUB7ELB6vMUugW4aSmZpBJOR6
=ZaJO
-----END PGP PUBLIC KEY BLOCK-----
------------------------------
Message: 9
Date: Sat, 12 Jun 2004 16:07:06 +0200
From: lu...@lupe-christoph.de (Lupe Christoph)
Subject: Re: Hacked or not appendice
To: Peter Rosa <pr...@pro.sk>
Cc: FreeBSD Security <freebsd-...@freebsd.org>
Message-ID: <2004061214...@lupe-christoph.de>
Content-Type: text/plain; charset=us-ascii
On Saturday, 2004-06-12 at 13:44:45 +0200, Peter Rosa wrote:
> I must add, there are no log entries after June 9, 2004. "LKM" message first
> apeared June 8, 2004, after this day, there is nothing in /var/messages,
> /var/security .....
Check if your syslog deamon is running. Also try to log something from
the command line with logger.
> How could I look for suspicious LKM module ? How could I find it, if the
> machine is hacked and I can not believe "ls", "find" etc. commands ?
Dunno. I've turned off modules on all my FreeBSD machines. IIRC, the
way to check binaries is to "make buildworld", install somewhere else
and compare. Of course, you should not build on a suspect machine.
Have you turned on securelevel?
HTH,
Lupe Christoph
--
| lu...@lupe-christoph.de | http://www.lupe-christoph.de/ |
| "... putting a mail server on the Internet without filtering is like |
| covering yourself with barbecue sauce and breaking into the Charity |
| Home for Badgers with Rabies. Michael Lucas |
------------------------------
Message: 10
Date: Sun, 13 Jun 2004 07:29:26 +1000
From: Peter Jeremy <Peter...@optushome.com.au>
Subject: Re: Hacked or not appendice
To: Thordur Ivar <th...@mi.is>
Cc: freebsd-...@freebsd.org
Message-ID: <2004061221...@cirb503493.alcatel.com.au>
Content-Type: text/plain; charset=us-ascii
On Sat, 2004-Jun-12 13:03:07 +0000, Thordur Ivar wrote:
>I have on a CD a number of binarys ( sources actually ) ( e.g. ls,
>find, grep, awk, sed, locate e.t.c. ) and when I belive that a
>machine has been cracked I remove the network cable from that machine
>and mount the cdrom build the sources and start looking. If I need
>something in that process I put it on my USB memstick from a 'trusted
>machine' and move it by hand over.
[Please wrap your mail before 80 characters]
Why would you trust the toolchain on a potentially hacked machine?
There's an old paper by Ken Thompson that dicusses patching the C
compiler to recognize the login sources and re-introduce a backdoor -
even it was removed from the login sources.
You would be much better off booting a fixit CD-ROM and using that
rather than trusting anything on the potentially hacked system.
--
Peter Jeremy
------------------------------
Message: 11
Date: Sun, 13 Jun 2004 01:54:08 +0200
From: Remko Lodder <re...@elvandar.org>
Subject: Re: [Freebsd-security] Re: Hacked or not appendice
To: Peter Jeremy <Peter...@optushome.com.au>
Cc: freebsd-...@freebsd.org
Message-ID: <40CB97A0...@elvandar.org>
Content-Type: text/plain; charset=us-ascii; format=flowed
Hey
Peter Jeremy wrote:
>
> [Please wrap your mail before 80 characters]
>
> Why would you trust the toolchain on a potentially hacked machine?
> There's an old paper by Ken Thompson that dicusses patching the C
> compiler to recognize the login sources and re-introduce a backdoor -
> even it was removed from the login sources.
>
> You would be much better off booting a fixit CD-ROM and using that
> rather than trusting anything on the potentially hacked system.
Indeed, one should make a backup copy (if possible) of the potentially
hacked computer (Drive) and take the machine offline.
Then insert the backupdisk in a other pc, (or the same, with the
original hd stored safely) and startup your Live-cd kit (which can be a
freebsd version from cd, or linux). Make sure that the tools necessary
are on the live cd;-) and to forensics (tct might help (The Coroners
Toolkit)..
After finding out what happened, format the disk, and reinstall from
scratch, be hostile to every config file and stuff you backupped,
because you might not be able to tell when the potential hack took
place.....
Cheers :-)
>
--
Kind regards,
Remko Lodder |re...@elvandar.org
Reporter DSINet |re...@dsinet.org
Projectleader Mostly-Harmless |re...@mostly-harmless.nl
------------------------------
Message: 12
Date: Sun, 13 Jun 2004 10:05:18 +0200
From: "Peter Rosa" <pr...@pro.sk>
Subject: Re: Hacked or not - RESULT
To: <freebsd-...@freebsd.org>
Message-ID: <002e01c4511d$2ad65ed0$3501...@pro.sk>
Hi all,
many thanks to everybody who showed me a way. I did not expect so many
advices :-)
As for me, this is the another confirmation, the FreeBSD is my favorite
system :-)
I have checked a machine using steps you have written, and the "lkm" message
seems to be a false positive.
Again, many thanks for all of you, boys.
Have a nice rest of weekend.
Peter Rosa
------------------------------
Message: 13
Date: Sun, 13 Jun 2004 11:15:47 +0200
From: Oliver Eikemeier <eike...@fillmore-labs.com>
Subject: FYI: new port security/portaudit-db
To: FreeBSD ports <FreeBS...@FreeBSD.org>
Cc: FreeBSD security <FreeBSD-...@FreeBSD.org>
Message-ID: <41764F4F-BD1A-11D8...@fillmore-labs.com>
Content-Type: text/plain; charset=US-ASCII; format=flowed
Dear porters and port users,
I've added a new port security/portaudit-db that complements
security/portaudit for users
that have a current ports tree and want to generate the portaudit
database themselves,
possibly distributing it over their local network. This will save you
the traffic downloading
information that is already on your local machine and avoid the lag that
is currently
associated with the mirroring process.
Basically you just need to install security/portaudit-db and do
`packaudit' every time after
your ports tree has been updated. Try `portaudit -d', it should show the
current date
afterwards.
This port also features a MOVED style file (database/portaudit.txt)
where UUIDs for vulnerabilities
can be allocated before they are researched thoroughly and moved to the
VuXML database. When you fix
a vulnerability in one of your ports, please add at least an entry to
this file, so that this fact
doesn't go unnoticed. Of course a full VuXML entry is preferred.
I take this announcement as an opportunity to make a plea to all port
maintainers:
* please stick with *one* PKGNAMESUFFIX (possibly using a combined one
like -sasl-client)
* please *do not* change the structure of the packages version number
according to included components.
Lets take for example port `myport' with has optional components c1 and
c2. This *should not*
result in the following package names:
port-v
port-suf1-v+v1
port-suf2-v+v2
port-suf1-suf2-v+v1+v2
because I need 2^(number of components) entries to catch all possible
combinations, for example the
recent vulnerability in www/apache13-modssl would need 32 entries in the
vulnerability database,
which seems a little high. A net effect is that many combinations are
not recognized, and users remain
unprotected even though they assume the opposite. If you need to record
the included components, please
do this in the pkg-message, which is displayed with pkg_info -D.
Again:
* a port should *not* change its version numbering based on included
components
* restrain yourself to *one* suffix in the package name (and use a dash
to seperate it from the main ports name)
Thanks
-Oliver
------------------------------
_______________________________________________
freebsd-...@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-securi...@freebsd.org"
End of freebsd-security Digest, Vol 63, Issue 6
***********************************************