Avian Gamers Network

Forum
It is currently Wed May 07, 2025 5:04 pm

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic  [ 17 posts ] 
Author Message
PostPosted: Sat Aug 21, 2004 12:14 pm 
Offline
Site Admin
User avatar

Joined: Mon Jul 01, 2002 4:33 am
Posts: 6698
Location: Silver Spring, MD
I need to scan my server (not home comp) for hidden Proxy Servers. I think I have some spam being sent from my sever.
Is there an Apache function that does this?

_________________
Moge


Top
 Profile  
 
 Post subject:
PostPosted: Sat Aug 21, 2004 12:25 pm 
Offline
Site Admin
User avatar

Joined: Wed Aug 08, 2001 8:01 pm
Posts: 5315
Location: Dublin
What OS?


Top
 Profile  
 
 Post subject:
PostPosted: Sat Aug 21, 2004 12:32 pm 
Offline
Site Admin
User avatar

Joined: Mon Jul 01, 2002 4:33 am
Posts: 6698
Location: Silver Spring, MD
Redhat with Apache 1.3.31
I also used Plesk (my WHM) to scan for Trojans. It found some possibles but I really don't knwo what my next steps are. If you have an article or even know of a norton-esk application to install for a server that scans and destroys these things please let me know.

I am very new at maintaining a remote server.

_________________
Moge


Top
 Profile  
 
 Post subject:
PostPosted: Sat Aug 21, 2004 2:42 pm 
Offline
Site Admin
User avatar

Joined: Wed Aug 08, 2001 8:01 pm
Posts: 5315
Location: Dublin
What exactly is the problem? What sort of spam, etc.


Top
 Profile  
 
 Post subject:
PostPosted: Sat Aug 21, 2004 2:46 pm 
Offline
Site Admin
User avatar

Joined: Mon Jul 01, 2002 4:33 am
Posts: 6698
Location: Silver Spring, MD
I have been getting 2-5 of these every few days now:

Quote:
From: "Returned mail" <postmaster@swg-decor.com>
Date: Sat Aug 21, 2004 10:47:13 AM US/Central
To: user02@swg-decor.com
Subject: Returned mail: see transcript for details
Attachments: There is 1 attachment


Dear user of swg-decor.com,

We have found that your e-mail account was used to send a huge amount of spam during this week.
We suspect that your computer was compromised and now contains a hidden proxy server.

Please follow the instructions in order to keep your computer safe.

Virtually yours,
The swg-decor.com team.

It comes with a Zip file attached.

_________________
Moge


Top
 Profile  
 
 Post subject:
PostPosted: Sat Aug 21, 2004 2:54 pm 
Offline
Site Admin
User avatar

Joined: Wed Aug 08, 2001 8:01 pm
Posts: 5315
Location: Dublin
Try these first to look for rootkits.
http://www.chkrootkit.org/
http://www.rootkit.nl/projects/rootkit_hunter.html


Top
 Profile  
 
 Post subject:
PostPosted: Sat Aug 21, 2004 3:19 pm 
Offline
Site Admin
User avatar

Joined: Mon Jul 01, 2002 4:33 am
Posts: 6698
Location: Silver Spring, MD
ok feel a little dumb here. I have it installed and I am sitting in teh directory. How do I actually run it?

Quote:
root@www [~/rkhunter]# rkhunter

Rootkit Hunter 1.1.6, Copyright 2003-2004, Michael Boelen

Rootkit Hunter comes with ABSOLUTELY NO WARRANTY. This is free software,
and you are welcome to redistribute it under the terms of the GNU General
Public License. See LICENSE for details.


Valid parameters:
--checkall (-c) : Check system
--createlogfile* : Create logfile
--cronjob : Run as cronjob (removes colored layout)
--display-logfile : Show logfile at end of the output
--help (-h) : Show this help
--nocolors* : Don't use colors for output
--report-mode* : Don't show uninteresting information for reports
--report-warnings-only* : Show only warnings (lesser output than --report-mode
,
more than --quiet)
--skip-application-check* : Don't run application version checks
--skip-keypress* : Don't wait after every test (non-interactive)
--quick* : Perform quick scan (instead of full scan)
--quiet* : Be quiet (only show warnings)
--update : Run update tool and check for database updates
--version : Show version and quit
--versioncheck : Check for latest version

--bindir <bindir>* : Use <bindir> instead of using default binaries
--configfile <file>* : Use different configuration file
--dbdir <dir>* : Use <dbdir> as database directory
--rootdir <rootdir>* : Use <rootdir> instead of / (slash at end)
--tmpdir <tempdir>* : Use <tempdir> as temporary directory

Explicit scan options:
--disable-md5-check* : Disable MD5 checks
--disable-passwd-check* : Disable passwd/group checks
--scan-knownbad-files* : Perform besides 'known good' check a 'known bad' che
ck

Multiple parameters are allowed
*) Parameter can only be used with other parameters

_________________
Moge


Top
 Profile  
 
 Post subject:
PostPosted: Sat Aug 21, 2004 3:23 pm 
Offline
Site Admin
User avatar

Joined: Wed Aug 08, 2001 8:01 pm
Posts: 5315
Location: Dublin
rkhunter -c
would seem to be it :)
Might be some useage docs on the site.

Or use rkhunter -h for help.
Might also be a Man page
man rkhunter


Top
 Profile  
 
 Post subject:
PostPosted: Sat Aug 21, 2004 3:27 pm 
Offline
Site Admin
User avatar

Joined: Mon Jul 01, 2002 4:33 am
Posts: 6698
Location: Silver Spring, MD
yeah their FAQ assumes your not a n00b like me. rkhunter -c and -h both worked.
It's is running now. I'll make a cron so this can run daily. The suck part is the FAQ said if it finds anything the only thing you can do is a clean install and it takes me days to do one of those :(

So far my system looks clean.

_________________
Moge


Top
 Profile  
 
 Post subject:
PostPosted: Sat Aug 21, 2004 3:35 pm 
Offline
Site Admin
User avatar

Joined: Mon Jul 01, 2002 4:33 am
Posts: 6698
Location: Silver Spring, MD
came up clean but have a few vulnerabilities:

Code:
* Application scan
   Checking Apache2 modules ...                               [ Not found ]
   Checking Apache configuration ...                          [ OK ]

* Application version scan
   - Exim MTA 4.24                                            [ Vulnerable ]
   - GnuPG 1.2.1                                              [ Vulnerable ]
   - Apache [unknown]                                         [ OK ]
   - Bind DNS [unknown]                                       [ OK ]
   - OpenSSL 0.9.7a                                           [ Vulnerable ]
   - PHP 4.3.8                                                [ OK ]
   - PHP 4.3.8                                                [ OK ]
   - Procmail MTA 3.22                                        [ OK ]
   - OpenSSH 3.6.1p2                                          [ Vulnerable ]



Security advisories
* Check: Groups and Accounts
   Searching for /etc/passwd...                               [ Found ]
   Checking users with UID '0' (root)...                      [ OK ]

* Check: SSH
   Searching for sshd_config...
   Found /etc/ssh/sshd_config
   Checking for allowed root login... Watch out Root login possible. Possible risk!
Hint: see logfile for more information
    info:
    Hint: See logfile for more information about this issue
   Checking for allowed protocols...                          [ Warning (SSH v1 allowed) ]

* Check: Events and Logging
   Search for syslog configuration...                         [ OK ]
   Checking for running syslog slave...                       [ OK ]
   Checking for logging to remote system...                   [ OK (no remote logging) ]


Thanks for your help Obo

_________________
Moge


Top
 Profile  
 
 Post subject:
PostPosted: Sat Aug 21, 2004 4:22 pm 
Offline
Site Admin
User avatar

Joined: Mon Jul 01, 2002 4:33 am
Posts: 6698
Location: Silver Spring, MD
poking arounf I noticed I never turned off TellNet after my last rebuild (opps). Also, do you run any LIDs apps?
I'm looking at installing one but Im a little unsure as the one Im looking at says I need to rebuild my Kernel and that freaks me out.

_________________
Moge


Top
 Profile  
 
 Post subject:
PostPosted: Sat Aug 21, 2004 6:09 pm 
Offline
n00b 4 3v3r
User avatar

Joined: Mon Sep 03, 2001 8:01 pm
Posts: 5412
Location: The Seaside, UK
iJasonT wrote:
I have been getting 2-5 of these every few days now:

Quote:
From: "Returned mail" <postmaster@swg-decor.com>
Date: Sat Aug 21, 2004 10:47:13 AM US/Central
To: user02@swg-decor.com
Subject: Returned mail: see transcript for details
Attachments: There is 1 attachment


Dear user of swg-decor.com,

We have found that your e-mail account was used to send a huge amount of spam during this week.
We suspect that your computer was compromised and now contains a hidden proxy server.

Please follow the instructions in order to keep your computer safe.

Virtually yours,
The swg-decor.com team.

It comes with a Zip file attached.
This is one of your bog-standard virus emails. Delete the mail and ignore it.

_________________
X2-PB

Pathfinder Kingmaker Campaign:
Gednan Malithanar - Wizard (1)
Dukin Thunderstrike - Ranger (1)

Star Citizen: - https://www.robertsspaceindustries.com/
AntanKarmola on their forums

Star Wars: The Old Republic: - Not really playing
Antare Karmola - Jedi Guardian (32)
Antan Karmola - Jedi Shadow (21)
Arianae Karmola - Gunslinger (20)


Top
 Profile  
 
 Post subject:
PostPosted: Sat Aug 21, 2004 6:20 pm 
Offline
User avatar

Joined: Wed Jun 19, 2002 6:54 am
Posts: 1561
Location: Oslo, Norway
yeah, looks like a MyDoom variant: here is the template MyDoom variant uses:

Quote:
Dear user {$t|of $T},{ {{M|m}ail {system|server} administrator|administration} of $T would like to {inform you{ that{:|,}|}|let you know {that|the following}{.|:|,}}|||||}

{We have {detected|found|received reports} that y|Y}our {e{-|}mail |}account {has been|was} used to send a {large|huge} amount of {{unsolicited{ commercial|}|junk} e{-|}mail|spam}{ messages|} during {this|the {last|recent}} week.
{We suspect that|Probably,|Most likely|Obviously,} your computer {had been|was} {compromised|infected{ by a recent v{iru}s|}} and now {run|contain}s a {trojan{ed|}|hidden} proxy server.

{Please|We recommend {that you|you to}} follow {our |the |}instruction{s|} {in the {attachment|attached {text |}file} |}in order to keep your computer safe.

{{Virtually|Sincerely} yours|Best {wishe|regard}s|Have a nice day},
{$T {user |technical |}support team.|The $T {support |}team.}


By opening the zip file, you run the risk of infecting your system with the worm (if your OS is vulnerable)

http://securityresponse.symantec.com/av ... .m@mm.html

_________________
Leno WeEda - Miner
Locin WeEda - Hauler/Trader


Last edited by Kyp Darron on Sat Aug 21, 2004 6:34 pm, edited 1 time in total.

Top
 Profile  
 
 Post subject:
PostPosted: Sat Aug 21, 2004 6:28 pm 
Offline
User avatar

Joined: Wed Jun 19, 2002 6:54 am
Posts: 1561
Location: Oslo, Norway
If you want to find out where these comes from, get the full header of the email, it should give us some clues (post it here if you want).

_________________
Leno WeEda - Miner
Locin WeEda - Hauler/Trader


Top
 Profile  
 
 Post subject:
PostPosted: Sat Aug 21, 2004 6:39 pm 
Offline
Site Admin
User avatar

Joined: Mon Jul 01, 2002 4:33 am
Posts: 6698
Location: Silver Spring, MD
Kyp Darron wrote:
By opening the zip file, you run the risk of infecting your system with the worm (if your OS is vulnerable)

reason number 10,000 I use my Mac to surf the web and check my email. It's so wonderful to never worry about what to open and what not to open. I have Norton on a Mac for a while but just took it off. I have never had a virus on my Mac in the 7+years I have had them.

_________________
Moge


Top
 Profile  
 
 Post subject:
PostPosted: Sat Aug 21, 2004 7:20 pm 
Offline
Site Admin
User avatar

Joined: Wed Aug 08, 2001 8:01 pm
Posts: 5315
Location: Dublin
hehe, I suppose I should have actually read the mail a bit closer :).
Still no harm hardening the box.


Top
 Profile  
 
 Post subject:
PostPosted: Sat Aug 21, 2004 7:24 pm 
Offline
Site Admin
User avatar

Joined: Mon Jul 01, 2002 4:33 am
Posts: 6698
Location: Silver Spring, MD
nope. Glad I did it actually. I had a few fatal errors in my security with Telnet and direct root access. Gave me a chance to firm it up and stretch my Linux legs which I don't get to do that often.
Also added a cool bit of code that sends me an email everytime someone logs in via root. It sends me the time, date and IP of the person that logs in. Kinda neat.

_________________
Moge


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 17 posts ] 

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group