From owner-freebsd-security@FreeBSD.ORG Sat Jun 12 14:08:53 2004 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 8B94416A4CE for ; Sat, 12 Jun 2004 14:08:53 +0000 (GMT) Received: from buexe.b-5.de (buexe.b-5.de [80.148.32.30]) by mx1.FreeBSD.org (Postfix) with ESMTP id 3222B43D1F for ; Sat, 12 Jun 2004 14:08:52 +0000 (GMT) (envelope-from lupe@lupe-christoph.de) Received: from antalya.lupe-christoph.de ([172.17.0.9])i5CE7CS20254; Sat, 12 Jun 2004 16:07:12 +0200 Received: from localhost (localhost [127.0.0.1]) by antalya.lupe-christoph.de (Postfix) with ESMTP id AE3BAB942; Sat, 12 Jun 2004 16:07:06 +0200 (CEST) Received: from antalya.lupe-christoph.de ([127.0.0.1]) by localhost (antalya [127.0.0.1]) (amavisd-new, port 10024) with LMTP id 16907-01-6; Sat, 12 Jun 2004 16:07:06 +0200 (CEST) Received: by antalya.lupe-christoph.de (Postfix, from userid 1000) id 9266FB886; Sat, 12 Jun 2004 16:07:06 +0200 (CEST) Date: Sat, 12 Jun 2004 16:07:06 +0200 To: Peter Rosa Message-ID: <20040612140706.GB1082@lupe-christoph.de> References: <019101c45072$a8b9cfe0$3501a8c0@pro.sk> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <019101c45072$a8b9cfe0$3501a8c0@pro.sk> User-Agent: Mutt/1.5.5.1+cvs20040105i From: lupe@lupe-christoph.de (Lupe Christoph) X-Virus-Scanned: by amavisd-new-20030616-p7 (Debian) at lupe-christoph.de cc: FreeBSD Security Subject: Re: Hacked or not appendice X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 12 Jun 2004 14:08:53 -0000 On Saturday, 2004-06-12 at 13:44:45 +0200, Peter Rosa wrote: > I must add, there are no log entries after June 9, 2004. "LKM" message first > apeared June 8, 2004, after this day, there is nothing in /var/messages, > /var/security ..... Check if your syslog deamon is running. Also try to log something from the command line with logger. > How could I look for suspicious LKM module ? How could I find it, if the > machine is hacked and I can not believe "ls", "find" etc. commands ? Dunno. I've turned off modules on all my FreeBSD machines. IIRC, the way to check binaries is to "make buildworld", install somewhere else and compare. Of course, you should not build on a suspect machine. Have you turned on securelevel? HTH, Lupe Christoph -- | lupe@lupe-christoph.de | http://www.lupe-christoph.de/ | | "... putting a mail server on the Internet without filtering is like | | covering yourself with barbecue sauce and breaking into the Charity | | Home for Badgers with Rabies. Michael Lucas |