Security Basics mailing list archives
RE: under attack
From: "Niek" <niek () packetstorm nu>
Date: Wed, 17 Mar 2004 12:06:01 +0100
-----Original Message----- From: Jorge Garcia [mailto:anarkophobia () linuxmail org] Sent: Monday, March 15, 2004 6:36 PM To: security-basics () securityfocus com Subject: under attack i discovered in my redhat server a openssh port open in port 1945 or somethin like that. now i filter the port with iptables but i want to do more. how can i close the port?? how can i get info about who did this and which program or prosses is using this port? how can i get any inpho about the attacker?? thanx
If you didn't install an openssh server on that port, someone else did. If that is the case, your box has been compromised probably. Firewalling some ports doesn't help in that case. (There are some rootkits which circumvent iptable rules!). Best advice would be to unplug the box immediately, back it up, and reinstall from read-only media (such as a cd-rom). Once installed, hook it up to the internet. (Make sure your box is either natted, or if connected directly, properly firewalled.) Now download the patches for your distro. Good luck, Niek --------------------------------------------------------------------------- Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off any course! All of our class sizes are guaranteed to be 10 students or less to facilitate one-on-one interaction with one of our expert instructors. Attend a course taught by an expert instructor with years of in-the-field pen testing experience in our state of the art hacking lab. Master the skills of an Ethical Hacker to better assess the security of your organization. Visit us at: http://www.infosecinstitute.com/courses/ethical_hacking_training.html ----------------------------------------------------------------------------
Current thread:
- under attack Jorge Garcia (Mar 16)
- RE: under attack Niek (Mar 17)
- Re: under attack Fernando Gont (Mar 17)
- Re: under attack Security Zone (Mar 17)
- <Possible follow-ups>
- RE: under attack Jonathan Pokrzyk (Mar 17)