From owner-freebsd-security@FreeBSD.ORG Thu Nov 17 15:54:33 2005 Return-Path: X-Original-To: freebsd-security@freebsd.org Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 759E716A41F for ; Thu, 17 Nov 2005 15:54:33 +0000 (GMT) (envelope-from reichert@numachi.com) Received: from meisai.numachi.com (meisai.numachi.com [198.175.254.6]) by mx1.FreeBSD.org (Postfix) with SMTP id D32D243D49 for ; Thu, 17 Nov 2005 15:54:32 +0000 (GMT) (envelope-from reichert@numachi.com) Received: (qmail 32860 invoked from network); 17 Nov 2005 15:54:29 -0000 Received: from natto.numachi.com (198.175.254.216) by meisai.numachi.com with SMTP; 17 Nov 2005 15:54:29 -0000 Received: (qmail 48413 invoked by uid 1001); 17 Nov 2005 15:54:29 -0000 Date: Thu, 17 Nov 2005 10:54:29 -0500 From: Brian Reichert To: Mark Jayson Alvarez Message-ID: <20051117155429.GD38047@numachi.com> References: <20051117012552.46503.qmail@web51607.mail.yahoo.com> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20051117012552.46503.qmail@web51607.mail.yahoo.com> User-Agent: Mutt/1.5.10i Cc: freebsd-security@freebsd.org Subject: Re: Need urgent help regarding security X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 17 Nov 2005 15:54:33 -0000 On Wed, Nov 16, 2005 at 05:25:52PM -0800, Mark Jayson Alvarez wrote: > Good Day! > > I think we have a serious problem. One of our old > server running FreeBSD 4.9 have been compromised and > is now connected to an ircd server.. > 195.204.1.132.6667 ESTABLISHED I had a 4.9 box compromised though the ssh install (I'm certain it wasn't openssh, but the base install), and was running an irc server itself. I just yanked the box off the net, and scrubbed it flat, and reinstalled. In my case, it wasn't worth the time to track who and when and how; I needed to put the server back on the net. Good luck on chasing them down. Are you sure that effort is worth it to you? > Thanks.. > > > > > __________________________________ > Yahoo! Mail - PC Magazine Editors' Choice 2005 > http://mail.yahoo.com -- Brian Reichert 55 Crystal Ave. #286 Daytime number: (603) 434-6842 Derry NH 03038-1725 USA BSD admin/developer at large