LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-02-2004, 03:39 PM   #1
mcalizo
Member
 
Registered: Aug 2003
Location: Manila, Philippines
Distribution: RH
Posts: 43

Rep: Reputation: 15
Forensics Step By Step


Anyone, Pls give me some step by step procedure on doing forensics for my suspected compromised server. I have been researching this for sometimes and i cant find a step by step procedure on doing that. Also i want to use any open source tools that are avialable for doing this procedure.
 
Old 05-02-2004, 04:30 PM   #2
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Take a look at post 5 of the security references thread by unSpawn. The are a number of forensics HOWTOs, including a step-by-step from CERT:

http://www.cert.org/tech_tips/root_compromise.html

The security references thread also has an extensive number of links to forensic tools and utils that should help you out. If you have any specific questions or need advice on doing the analysis, feel free to post them.
 
Old 05-02-2004, 11:10 PM   #3
mcalizo
Member
 
Registered: Aug 2003
Location: Manila, Philippines
Distribution: RH
Posts: 43

Original Poster
Rep: Reputation: 15
Tnx Capt_caveman.. I will try to look at it.
 
Old 05-02-2004, 11:34 PM   #4
-Nw- neX
Member
 
Registered: Apr 2004
Distribution: Gentoo, RHL, CentOS, Ubuntu, FreeBSD,
Posts: 88

Rep: Reputation: 15
ran across these the other day in the news. might help you out.

'Forensic Analysis of a Live Linux System, Part One'
http://www.securityfocus.com/infocus/1769

'Forensic Analysis of a Live Linux System, Part Two'
http://www.securityfocus.com/infocus/1773
 
Old 05-03-2004, 01:21 AM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Mcalizo, I think forensics could be easier when you tap into the collective power of LQ, so could you at least tell us the symptoms the box displays or alerts you've gotten?
 
Old 05-03-2004, 01:51 AM   #6
mcalizo
Member
 
Registered: Aug 2003
Location: Manila, Philippines
Distribution: RH
Posts: 43

Original Poster
Rep: Reputation: 15
unSpawn i got a RH9.0 web server, last week i run chkrootkit (as i always do daily), i found that su is infected. I also run rkhunter to verify the result and the same output comes out. But the worse case is there's a lot of spoof IP trying to connect to that server when i run iptstate and iptraf. So i isolated that server and replace another "hardened" server, but still i can monitor a lot of attempted connection using port 80. Those connection ( though not sucessfull) make our bandwitdh utilization to maximum.
 
Old 05-03-2004, 11:51 AM   #7
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
last week i run chkrootkit (as i always do daily), i found that su is infected.
If you check Chkrootkit it'll do a grep. Could you please post the output of running:
strings -an1 | egrep -ie "(satori|vejeta|conf)"
This should rule out false positives.


I also run rkhunter to verify the result and the same output comes out.
If you check Rootkit Hunter it'll do a md5sum check, and that may not match your su version. Could you please post the output of running this, it's a quick way of checking md5sum with rpm contents (sh-utils from running "rpm -q --whatprovides /bin/su"):
rpm -q --dump sh-utils | grep "n/s"
md5sum /bin/su


So i isolated that server
How did you isolate it (yank/reconnect network cable, power down, other)? Where is it located (isolated subnet?)? Is it still up without reboot? Any chance of getting account, process and network details? Logs? If you powered it down I hope you didn't reboot it.
[EDIT]
I mean a dead server should be left dead until the coroner has done it's job. Resurrection could result in all sorts of weirdness (or nothing, but are you willing to take the chance...).
[/EDIT]


but still i can monitor a lot of attempted connection using port 80. Those connection ( though not sucessfull) make our bandwitdh utilization to maximum.
Do you run an IDS (like Snort or Prelude)? Or Ethereal or tcpdump? Any chance of getting tcpdump output?


BTW, did you read the stuff CC told you about?

Last edited by unSpawn; 05-03-2004 at 12:01 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Step-By-Step Instruction to install Linksys WPC11 Ver.4 Wireless Card Zypher Linux - Hardware 8 08-12-2009 10:43 AM
Step by Step guied for Installation pent@net Dvb card under linux mobassir Linux - Networking 4 06-07-2006 07:31 PM
I need a step by step help to instal Suse 9.3 Pro on the same hdd as XP Home & 2003 suse91pro Linux - General 4 09-07-2005 01:15 PM
Step-by-Step: Making integrated Broadcome wireless adapter work with Mandrake 9.2 jmp875 Linux - Wireless Networking 16 06-30-2004 12:50 AM
Installing Mandrake Linux 10, step by step tutorial for Windows users lucat Linux - Newbie 0 06-12-2004 06:03 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:48 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration