How-to Detect A Possible Intruder ¿?

May 22, 2007

I have a few incomplete steps to see if I got some intruder in my Linux system.. But i really would like to have all your suggestions to make a good doc about this matter,

1.- Download and run Rkhunter & Chkrootkit
2.- Run "w", and "netstat -nalp |grep "SHPORTHERE" to see whos connected using SSH
3.- Search for ssh and ftp accepted logins.

Code:
last
cat /var/log/secure* | grep ssh | grep Accept
cat /var/log/secure* |grep ftp |grep Accept
less /var/log/messages | grep ftp
4.- Watch current connections and scan your ports.

Code:
netstat -nalp
nmap 1-65535 localhost
5.- Search for suspicious content on common explotable dirs.

Code:
rm -rf /tmp/sess*
rm -rf /var/dos-*
rm -rf /var/tmp/ssh-*
rm -rf /var/tmp/dos-*
ls /tmp -lab
ls /var/tmp -labR
ls /dev/shm -labR
ls /usr/local/apache/proxy -labR
ls /usr/local/samba -labR
6.- Checking for anomalies on this files.

Code:
less /etc/passwd
less /etc/shadow
less /etc/groups
7.- Search for new users at sudoers, check wtmp and telnet is not running.

Code:
cat /etc/sudoers
who /var/log/wtmp
cat /etc/xinetd.d/telnet
8.- Find bash history files

Code:
find '/' -iname .bash_history
9 .- Verify the Crontab table

Code:
crontab -l
10 .- Update the slocate database and search for exploits.

Code:
updatedb &
For cPanel servers:

Code:
egrep -i '(chr(|system()|(curl|wget|chmod|gcc|perl)%20' /usr/local/apache/logs/*
egrep -i '(chr(|system()|(curl|wget|chmod|gcc|perl)%20' /home/*/statistics/logs/*
For Ensim servers:

Code:
egrep -i '(chr(|system()|(curl|wget|chmod|gcc|perl)%20'/home/virtual/site*/fst/var/log/httpd/*
Search for shell code:

Code:
cat /path/of/your/web/logs/* |grep "/x90/"
11.- Search for hidden dirs

Code:
locate "..."
locate ".. "
rlocate " .."
locate ". "
locate " ."
12.- Search for perl-scripts running

Code:
ps -aux | grep perl
13 .- Checking nobody user and open files.

Code:
service httpd stop
lsof -u nobody

View 14 Replies


ADVERTISEMENT

How To Detect Spamming

Apr 21, 2009

How do you know your clients are sending bulk/spam emails?

I don't seem to understand the reports in "Email >> View Mail Statistics" section of WHM.

View 5 Replies View Related

Detect Memory

Jul 25, 2009

I have a private vps server works under linux ( centos ), sometimes am getting msg from csf/firewall subject:

lfd on website.com: Suspicious process running under user user account

when i check my cpanel/whm vps ( service status ) its shows that the memory limit 80% - 85% , It's had a good forum works with vb, but am wonder how to check my vps memory, i mean how to detect if there any script, or malware, or anything takes the vps memory out...

Is there any way to check,know what works under my vps, so it's take my memory limit 85%?

i check the tmp folder,

root@www [/home]# cd /tmp
root@www [/tmp]# ls -la
total 364
drwxrwxrwt 6 root root 4096 Jul 25 02:14 ./
drwxr-xr-x 21 root root 4096 Jul 18 02:21 ../
drwxrwxrwt 2 root root 4096 Jun 30 05:50 .ICE-unix/
drwxrwxrwx 18 root root 4096 Jul 2 17:33 eaccelerator/
lrwxrwxrwx 1 root root 27 Jul 18 02:13 mysql.sock -> ../var/lib/mysql/mysql.sock=
drwxr-xr-x 3 root root 4096 Jun 30 05:29 pear/
drwx------ 3 root root 4096 Jul 5 18:31 spamd-23647-init/
-rw------- 1 root root 343335 Jul 19 02:50 whatis.bk6140
root@www [/tmp]# cd /home
and the df space

root@www [~]# df -h
Filesystem Size Used Avail Use% Mounted on
/dev/simfs 80G 4.1G 76G 6% /
root@www [~]#
and the services running is

USER PID %CPU %MEM VSZ RSS TTY STAT START TIME COMMAND
root 1 0.0 0.0 2060 156 ? Ss Jun30 1:23 init [3]
root 7465 0.0 0.0 2444 156 ? S Jul03 0:00 /bin/sh /usr/bin/mysqld_safe --datadir=/var/lib/mysql --pid-file=/var/lib/mysql/www.website.com.pid
mysql 7491 0.0 2.5 33452 10440 ? Sl Jul03 11:33 /usr/sbin/mysqld --basedir=/ --datadir=/var/lib/mysql --user=mysql --pid-file=/var/lib/mysql/www.website.com.pid --skip-external-locking
root 10236 0.0 6.0 27396 24764 ? Ss Jul24 0:07 /usr/bin/spamd -d --allowed-ips=127.0.0.1 --pidfile=/var/run/spamd.pid --max-children=3 --max-spare=1
root 11447 0.0 1.9 18364 8020 ? S Jul24 0:00 cpsrvd - waiting for connections
root 11865 0.0 0.7 13672 3260 ? S Jul06 0:00 /usr/local/apache/bin/httpd -k start -DSSL
root 13537 0.0 3.1 15092 13064 ? Ss 00:00 0:02 lfd - sleeping
root 13703 0.0 0.3 3808 1284 ? SN Jul06 0:01 cpanellogd - sleeping for logs
root 13739 0.0 0.6 5856 2844 ? Ss Jul06 0:00 cPhulkd - processor
root 13795 0.0 1.5 14760 6304 ? S Jul06 0:00 cpdavd - accepting connections on 2077 and 2078
root 18161 0.0 0.0 1716 380 ? Ss Jun30 0:24 syslogd -m 0
root 18164 0.0 0.0 1668 72 ? Ss Jun30 0:00 klogd -x
dbus 18193 0.0 0.0 2736 212 ? Ss Jun30 0:00 dbus-daemon --system
root 18213 0.0 0.0 2716 172 ? Ss Jun30 0:00 xinetd -stayalive -pidfile /var/run/xinetd.pid
root 18399 0.0 5.9 27604 24404 ? S Jul24 0:06 spamd child
root 19461 0.0 0.1 3228 684 ? Ss Jun30 0:08 crond
root 19616 0.0 0.0 1820 124 ? Ss Jun30 0:00 /usr/sbin/portsentry -

View 7 Replies View Related

How To Detect Flood Ftp

May 4, 2008

My server run after 10h sevices ftp is down (network error: connection timed out). may be flood ftp.

how to Detect flood ftp.

View 4 Replies View Related

Detect Errors On Server

Apr 6, 2009

I have a server of my own. Unfortunatlly 20% of the time, the server is down even though my connection to internet always up.

I am checking the event log but cannot see anything odd...
OS:Windows server 2003

Is there any tool to detect why the server is down most of the time?

I can post the event viewer errors that I can find suspeicious if needed.

View 2 Replies View Related

How To Detect A DDoS Attack ...

May 19, 2009

is there any proved method to determine what kind of attack you are under? Our server has been under attack for more than a day now but so far we have not been able to find out what kind of attack it is exactly. The server maintence company we are using says it's a DDoS attack but they don't say how they found this out. Also, they are not telling us what kind of DDoS attack it is.

View 14 Replies View Related

Is It Possible To Detect User's Pc Configuation

Jul 31, 2009

i have some issue,

sometimes,a user may be banned by our firewall,

or the dns of his pc does not work well,...and so on,

by the way,

they can not link to server,

and it spend a lot of time to check where is wrong from his pc aside.

i want to ask if it is possible i use a php script or a exe let him to execute,

and it will help me detect user's pc configuation,

it include his IP/DNS/fateway/trace and ping result,...and so on.

View 4 Replies View Related

How To Detect A VPS And Its Technology In Linux

Jul 25, 2008

Is there any way to distinguish a dedicated server from VPS using Linux commands and detect the implemented virtualization technology like XEN and OpenVZ, ...?

I have received a dedicated server and in cPanel its written Virtuozzo but they tell me it's XEN , beside this what's the reason to implement a virtualization technic while they give me a dedicated server? Maybe to obtain cheaper cPanel license,

View 8 Replies View Related

Host Ability To Self Detect

Nov 13, 2008

Do web hosts have the means to self-detect or self-correct problems with people's websites? If so, is there a name for this ability?

Seems that every host I've used has to be *told* about major problems, such as the server or database being down completely. I'm tired of going out of town fearing a site crash. I don't expect them to catch every problem, but when the failure is so blatant, it would be nice if they caught it...

How would I find a host who does this?

View 11 Replies View Related

How To Detect Is It Domain Name Server (DNS) Or Http Down?

Aug 1, 2009

If i put domain.com on uptime checker,and downtime is detected,downtime will be reported if dns is down or if http server is down.So question is what i need to do to see what exactly went down?For network uptime i can ping ip adress,but for these two i really don't know.

View 3 Replies View Related

C99Shell :: Detect And Disable C99 Shell?

Aug 15, 2008

how i can detect and disable C99 shell and another shell script exp:r57 ....

View 9 Replies View Related

Detect The Costa Rica ISP's Website

Sep 28, 2009

I know the ISP is RADIGRAFICA COSTARRICENSE, and the server location is San José in Costa Rica.

I googled the ISP name RADIGRAFICA COSTARRICENSE, trying to find out the company site which offer's web hosting service, but I can only find racsa.co.cr; however, this doesn't look like a web hosting company.

View 2 Replies View Related

How To Detect What Exactly Caused High Load

Aug 2, 2009

On one server which i have sometime appear very high load up to 70,and that causing downtime of few minutes(i have historic data webmin module where i saw high load and downtime time matches,but it doesn't show what causing it).That server also have hardware raid in mirror mode.(copies exact data from one disk to another).

View 14 Replies View Related

Hacked Vps, To Many Files, How To Detect Hacker

May 6, 2009

Sometime ago the DC told me there was too many files on server and I started to investigate what is was and i got info that some one hacked the server and was sending spam from it.

When I looked at the accounts in Direct Admin some of them had the contact email to some hacker so i deleted the emails and changed password on the DA account and the email of those accounts.

Still I got too many files all the time so the server goes down so i have to delete the spoolfile all the time like 10 times a day

Please help how do I detect from what account do the hacker operate?

Can I detect that somehow?

Is it possible to do some small script to detect this?

Is there any advanced module to DA that gives me the info?

View 5 Replies View Related

Detect Mail Server Software

Oct 29, 2007

How does one go about detecting what mail server software you have installed and running on your server?

View 2 Replies View Related

How To Detect The Type Of HDDs Installed On My CentOS

Jan 10, 2007

Everything I found is the type of RAID controller installed. It's Adaptec 4800SAS SA-SCSI RAID-10. Nothing in /proc about types of HDDs.

View 7 Replies View Related

How To Auto Detect A Hack Local File

Dec 12, 2007

My server running centOS4 and cPAnel.

Can anyone let me know how to auto detect a hack local file ? eg: review cgi-telnet, c99sell ....

View 4 Replies View Related

Apache :: How To Detect Where User Has Come From A Specific Website

Nov 1, 2013

configure Apache server to handle users requests using condition based on where he come from so i can redirect him . what i need if user came with from site start with xn--* redirect him to virtual host and if he came from any other link then go to another virtual host

View 2 Replies View Related

How To Detect Raid Harddisk Specs From Command Line

Feb 22, 2008

how can i remotly( SSH) figure out what kind of raid controller is on my system?!
and how many harddisks my system has and what size?!

I am working on Linux( Centos4)

if i do
#df -h
then i get 146 G

so if my system has raid1, does it mean that the harddisk is 2 X 146 G?
or i should actually see it as 146 / 2?

View 5 Replies View Related

How Do You Detect And Block Ddos Or Large Number Of Connection

Nov 7, 2008

sometimes, some people may try to guess the password of ssh,whm,ftp,...etc,

or any ddos attack,

do you only use iptables to place this problem?

or do you install any other scripts to secure your server?

my serve is centso.

View 6 Replies View Related

How Do I Detect And Remove Spyware From Windows 2003 Server

Mar 22, 2007

I am suspecting that we have spyware or virus on our server. How do I detect and remove it from windows 2003 server?

View 6 Replies View Related

Apache :: How To Detect Wamp And Ignore Some HTAccess Lines

May 12, 2013

My linux host requires a few lines of codes in my .htaccess file to properly run my site.

However, these few lines of codes are not supported by my local Wamp on Win7.

Is there a way to add a "If Wamp Then not run these lines" in my htaccess file

So that I don't have to manually change the .htaccess file before upload/downloading the site between the two systems?

View 2 Replies View Related

Command Line To Detect Account/file With Video/music

Feb 20, 2007

What command line do you use to detect account storing music/video?

What command line do you search for file that is greater than 1MB?

View 1 Replies View Related

C99Shell :: How To Detect Or Disable The Functionality Of C99Shell

Jul 13, 2008

Recently my site was defaced, (i own a dedicated server), my server was not touched, but one of the applications I used on the site was exploited to gain access to it.

I have noticed 4 or 5 c99 shells in different locations on my ftp. The site is back online, but it's definitely possible that they have one of these hidden somewhere and that they'll just do it again. I am using cent os 5

How can I easily search for these on my box? Can I disable their functionality? is there setting I can use in htaccess or something to make my website safer? I visited one of the scripts, and it said SAFEMODE OFF, how can I at least enable safemode?

I don't know much of anything about linux, but I am running cpanel and WHM. I have a guy who manages my box but he is hard to get a hold of sometimes, and I'd like to take care of this ASAP!

View 6 Replies View Related

How Detect Paths Of ImageMagick And Test ImageMagick?

Jan 22, 2008

I buy some webhosts from various hosting providers. I installed vBulletin on one host and ImageMagick do not work. Hosting provider said ImageMagick is installed. Also I checked phpinfo and sow it is really installed. But ImageMagick still do not work!

So, I need anything to detect real ImageMagick paths, status, components.
and also I need anything to test ImageMagick if it works or not.

View 10 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved