Kasper Dupont wrote:
> "Schultz Consult - [René Madsen]" wrote:
>
>>Kasper Dupont wrote:
>>
>>>Hvis en zombie process eksisterer i længere tid, må
>>>der være noget galt. Og hvis den samtidigt bliver ved
>>>med at bruge CPU tid, så er der noget rivende galt.
>>>
>>
>>Altså er der noget rivende galt
for de eksistere lige fra "angrebet"
>>starter til jeg genstarter maskinen,
>
>
> Er deres process ID det samme hele tiden?
>
>
>>Kan det have noget med
>>
http://www.securitynet.cz/modules.php?name=News&file=article&sid=351
>
>
> Det ved jeg ikke.
>
>
>>Det er kun perl processerne der løber løbsk og de er startet af www, som
>>er apache brugeren
>
>
> Jeg ville prøve at bruge strace eller noget lignende.
>
>
>>Kunne det have nogen sammenhæng?
>>
>>Kommer med dumps fra ethereal når jeg lige får fundet de dele der er
>>interessante
>
>
> OK, det vil i hvert fald være bedre end de logs du
> sendte tidligere.
Her kommer så lige et godt dump
Internet Protocol, Src Addr: 195.197.175.21 (195.197.175.21), Dst Addr:
xxx.xxx.xxx.xxx (xxx.xxx.xxx.xxx)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00)
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..0. = ECN-Capable Transport (ECT): 0
.... ...0 = ECN-CE: 0
Total Length: 1101
Identification: 0xbc4b (48203)
Flags: 0x04
0... = Reserved bit: Not set
.1.. = Don't fragment: Set
..0. = More fragments: Not set
Fragment offset: 0
Time to live: 58
Protocol: TCP (0x06)
Header checksum: 0xff5a (correct)
Source: 195.197.175.21 (195.197.175.21)
Destination: xxx.xxx.xxx.xxx (xxx.xxx.xxx.xxx)
Transmission Control Protocol, Src Port: ircd (6667), Dst Port: 1241
(1241), Seq: 143, Ack: 79, Len: 1049
Source port: ircd (6667)
Destination port: 1241 (1241)
Sequence number: 143
Next sequence number: 1192
Acknowledgement number: 79
Header length: 32 bytes
Flags: 0x0018 (PSH, ACK)
0... .... = Congestion Window Reduced (CWR): Not set
.0.. .... = ECN-Echo: Not set
..0. .... = Urgent: Not set
...1 .... = Acknowledgment: Set
.... 1... = Push: Set
.... .0.. = Reset: Not set
.... ..0. = Syn: Not set
.... ...0 = Fin: Not set
Window size: 2896
Checksum: 0x9c00 (correct)
Options: (12 bytes)
NOP
NOP
Time stamp: tsval 186247759, tsecr 2065064
Internet Relay Chat
Response Line: :Helsinki.FI.EU.Undernet.org 001 FloodBot :Welcome
to the UnderNet IRC Network via EUnet Finland, FloodBot
Response Line: :Helsinki.FI.EU.Undernet.org 002 FloodBot :Your host
is Helsinki.FI.EU.Undernet.org, running version u2.10.12.beta.09
Response Line: :Helsinki.FI.EU.Undernet.org 003 FloodBot :This
server was created Fri Jul 15 2005 at 13:00:56 EEST
Response Line: :Helsinki.FI.EU.Undernet.org 004 FloodBot
Helsinki.FI.EU.Undernet.org u2.10.12.beta.09 dioswkgx biklmnopstvrD bklov
Response Line: :Helsinki.FI.EU.Undernet.org 005 FloodBot WHOX
WALLCHOPS WALLVOICES USERIP CPRIVMSG CNOTICE SILENCE=15 MODES=6
MAXCHANNELS=20 MAXBANS=45 NICKLEN=12 MAXNICKLEN=15 TOPICLEN=160
AWAYLEN=160 KICKLEN=160 CHANNELLEN=200 MAXCHANNEL
Response Line: :Helsinki.FI.EU.Undernet.org 005 FloodBot
CHANTYPES=#& PREFIX=(ov)@+ STATUSMSG=@+ CHANMODES=b,k,l,imnpstrD
CASEMAPPING=rfc1459 NETWORK=UnderNet :are supported by this server
Response Line: :Helsinki.FI.EU.Undernet.org 251 FloodBot :There are
34806 users and 75939 invisible on 25 servers
Response Line: :Helsinki.FI.EU.Undernet.org 252 FloodBot 65
erator(s) online
et meget langt stykke dump med en masse IRC haløj...
Internet Protocol, Src Addr: 195.197.175.21 (195.197.175.21), Dst Addr:
xxx.xxx.xxx.xxx (xxx.xxx.xxx.xxx)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00)
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..0. = ECN-Capable Transport (ECT): 0
.... ...0 = ECN-CE: 0
Total Length: 157
Identification: 0xbceb (48363)
Flags: 0x04
0... = Reserved bit: Not set
.1.. = Don't fragment: Set
..0. = More fragments: Not set
Fragment offset: 0
Time to live: 58
Protocol: TCP (0x06)
Header checksum: 0x026b (correct)
Source: 195.197.175.21 (195.197.175.21)
Destination: xxx.xxx.xxx.xxx (xxx.xxx.xxx.xxx)
Transmission Control Protocol, Src Port: ircd (6667), Dst Port: 1241
(1241), Seq: 87058, Ack: 233, Len: 105
Source port
: ircd (6667)
Destination port: 1241 (1241)
Sequence number: 87058
Next sequence number: 87163
Acknowledgement number: 233
Header length: 32 bytes
Flags: 0x0018 (PSH, ACK)
0... .... = Congestion Window Reduced (CWR): Not set
.0.. .... = ECN-Echo: Not set
..0. .... = Urgent: Not set
...1 .... = Acknowledgment: Set
.... 1... = Push: Set
.... .0.. = Reset: Not set
.... ..0. = Syn: Not set
.... ...0 = Fin: Not set
Window size: 2896
Checksum: 0xef81 (correct)
Options: (12 bytes)
NOP
NOP
Time stamp: tsval 186372766, tsecr 2075732
Internet Relay Chat
Response Line: :aluP!root@aluP.users.undernet.org PRIVMSG
#bimartethakiya
shellcmd /tmp/.bashrc 217.158.132.142 22 0
Frame 117564 (112 bytes on wire, 112 bytes captured)
Arrival Time: Jul 19, 2005 18:26:04.075282000
Time delta from previous packet: 0.000551000 seconds
Time since reference or first frame: 17861.245181000 seconds
Frame Number: 117564
Packet Length: 112 bytes
Capture Length: 112 bytes
Ethernet II, Src: 00:30:6e:05:92:7f, Dst: 00:07:b3:8c:cc:00
Destination: 00:07:b3:8c:cc:00 (xxx.xxx.xxx.yyy)
Source: 00:30:6e:05:92:7f (xxx.xxx.xxx.xxx)
Type: IP (0x0800)
xxx.xxx.xxx.xxx er freebsdmaskinens IP adresse og xxx.xxx.xxx.yyy er
dens gateway, adresserne er sløret for en sikkerhedsskyld
busted...
/tmp/.bashrc 217.158.132.142 22 0
eller en ligende kommando har ofte stået som kørende i en ps -aux...
Det næste spørgsmål er så, hvordan er den fil så kommet ind på min
maskine og hvordan er det lige at de kan have noget IRC haløj kørende
"hen over" min maskine...
--
Med venlig hilsen
René Madsen
Schultz Consult