Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
You may already be hacked.
Jon Lasser, 2001-07-25

Rootkits help hackers play hide-and-seek.

Comments Mode:
LOVE YOU MAN!!! 2001-07-25
elliptic (5 replies)
Ports 2001-07-26
Zer0
LOVE YOU MAN!!! 2001-08-01
cds@hotmail.com
LOVE YOU MAN!!! 2001-08-02
logarithm
LOVE YOU MAN!!! 2001-08-07
Anonymous
LOVE YOU MAN!!! 2001-08-13
Dark Spaniel
Fuq1n l0zer 2001-07-26
gr4nd 1nqu1z1t0r (1 replies)
mmm? 2002-02-08
Anonymous
bugs 2001-07-30
walterp@fuse.net
Why surf as root 2001-08-03
Rodrigo Ramos <ramos@ipad.com.br>
great article. 2001-08-05
Gonçalo Gomes
what about strace 2001-08-10
arne.peer@appelmoes.xs4all.be
You may already be hacked - by a script? 2002-01-08
Anonymous
Greetings.

I recently put together a box for running an IP chains-based linux firewall.

Being rahter naive about how rapidly the system could get hacked, I opened an Internet-facing interface for testing purposes. The system was compromised in less than 24 hours! and get this - I was logged in watching as the system was attacked and compromised!! consequently, I was able to get the on-site people on the phone and have them drop power to the system, practically on my command.

As a result, I was able to capture their rootkit, both in its pre-installed and it's up-and-running state, and was able to perform a full (if amatuerish =) post-mortem analysis of the system.

Highly interesting stuff! I could grok much of what they were doing, though admittedly some of it was beyond my casual reckoning - as best I could tell the rootkit was automated, searching networks for exploitable systems, implanting itself therein, and periodically reporting back to its owners/operators through email addresses at yahoo.

If anyone is interested (and qualified), I actually have their stuff on a cd, pretty much in toto (I have no way of knowing if they were able to dispose of more than what I was able to bring back from deletion on the ext2 fs).

Interested parties give me a shout at alteridentity@yahoo.com

-James


[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/12/9730#9730







 

Privacy Statement
Copyright 2009, SecurityFocus