Avi Alkalay Digital Awareness and Flying Spirit
How to Get Attacked 1 comment By AviPublished: Tue, 07 Aug 2007 11:38:47 -0300 Updated: Sat, 25 Oct 2008 07:36:49 -0200 Published: 7 Aug 2007 Updated: 25 Oct 2008 Published: 11:38 am Updated: 7:36 am Categories: Linux & Open Source Tags:

I noticed Oded’s blog was attacked which makes me remember some things:

I was once invited to analyze a Linux machine that was invaded. I ended up writing an article about it to the brazilian Linux Magazine.

The problem with the machine was a VERY weak root passw0rd. We could also find the tools they used to break that machine, cause they have installed them there to attack other machines.

We could see a file containing about 18000 user+password combinations, a modified SSH client and a script that runs it all based on an IP range. We saw also IRC bots and other stuff.

In the case of that machine, the attack was silent. They just wanted to use the machine to attack other machines. Pretty stupid.

Its easy to learn about this attacks. Just connect to the Internet a machine with a plain Linux installation and “passw0rd” as the root’s password, wait 1 or 2 weeks and your machine will be attacked. One way to verify the crackers are already in is to reinstall the netstat command (because they’ll modify your previous one) and see if there is some connection to IRC ports (around 6667).

If you investigate this IRC bot you’ll able to connect the IRC server, find the chat room, and actually talk to the cracker. I did this once and was not very funny.

More information in Attacks to GRC.com by Steve Gibson.

Leave a Reply

XHTML: You can use these tags:<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

  One Response to “How to Get Attacked”

#1

Number one thing I do on a publicly accessible system is disable root from ssh access.

Avi Alkalay is powered by WordPress 2.6.3 and delivered to you in 1.204 seconds using 25 queries.

Theme: Plasma, your last WordPress theme by Avi Alkalay.

Icons by the Blog Icons Project.