From owner-freebsd-security@FreeBSD.ORG Sat May 10 11:05:09 2003 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 34BD837B401 for ; Sat, 10 May 2003 11:05:09 -0700 (PDT) Received: from smtp-27.ig.com.br (smtp-27.ig.com.br [200.226.132.159]) by mx1.FreeBSD.org (Postfix) with SMTP id B14A343F3F for ; Sat, 10 May 2003 11:05:07 -0700 (PDT) (envelope-from none@superig.com.br) Received: (qmail 23236 invoked from network); 10 May 2003 18:05:13 -0000 Received: from unknown (HELO superig.com.br) (200.179.208.42) by smtp-27.ig.com.br with SMTP; 10 May 2003 18:05:13 -0000 Message-ID: <3EBD3FBD.2030007@superig.com.br> Date: Sat, 10 May 2003 15:06:53 -0300 From: Tony Meman User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.0.0) Gecko/20020623 Debian/1.0.0-0.woody.1 X-Accept-Language: en MIME-Version: 1.0 Cc: freebsd-security@freebsd.org References: <200305101116.h4ABGMH21903@boyes.its.utas.edu.au> Content-Type: text/plain; charset=us-ascii; format=flowed Content-Transfer-Encoding: 7bit Subject: Re: Hacked? X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 10 May 2003 18:05:09 -0000 You should search the logs for weird exit msgs from the daemons. You could also look for core dumped files in the file system. If you still can't find a good bet would be in Samba (were you running it? which version?) and OpenSSL/apache. -- none Adam Dewis wrote: > > Doing a complete reeinstall is all good and well, but Installing a > rootkit means that the cracker used a hole to gain the required > permissions to do so. Whcih in praticality means that you will need to > patch the hole as well, unfortunatly I cannot offer any advice on > finding the hole, but mayhaps some other security guru on this list may > be able to steer you in the right direction? > > Adam >