Security Basics mailing list archives

RE: under attack


From: "Niek" <niek () packetstorm nu>
Date: Wed, 17 Mar 2004 12:06:01 +0100

-----Original Message-----
From: Jorge Garcia [mailto:anarkophobia () linuxmail org] 
Sent: Monday, March 15, 2004 6:36 PM
To: security-basics () securityfocus com
Subject: under attack


i discovered in my redhat server a openssh port open in port 
1945 or somethin like that.
now i filter the port with iptables but i want to do more.
how can i close the port??
how can i get info about who did this and which program or 
prosses is using this port?
how can i get any inpho about the attacker??
thanx

If you didn't install an openssh server on that port, someone else did.
If that is the case, your box has been compromised probably.
Firewalling some ports doesn't help in that case.
(There are some rootkits which circumvent iptable rules!).

Best advice would be to unplug the box immediately, back it up,
and reinstall from read-only media (such as a cd-rom).
Once installed, hook it up to the internet. (Make sure
your box is either natted, or if connected directly, properly
firewalled.)
Now download the patches for your distro.

Good luck,

Niek


---------------------------------------------------------------------------
Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off 
any course! All of our class sizes are guaranteed to be 10 students or less 
to facilitate one-on-one interaction with one of our expert instructors. 
Attend a course taught by an expert instructor with years of in-the-field 
pen testing experience in our state of the art hacking lab. Master the skills 
of an Ethical Hacker to better assess the security of your organization. 
Visit us at: 
http://www.infosecinstitute.com/courses/ethical_hacking_training.html
----------------------------------------------------------------------------


Current thread: