Syngin
12-04-2001, 03:02 PM
Hey guys,
Sendmail died on our primary web server and our server provider is saying that its been compromised. He's put the following forth as proof:
SM5....T /bin/ps
SM5....T /usr/bin/top
.M...... /usr/bin/crontab
S.5..UGT /usr/bin/bzip2
S.5....T c /sbin/ifup
missing /usr/bin/wget
S.5..UGT /usr/bin/ncftpput
S.5....T /bin/netstat
S.5....T /sbin/ifconfig
SM5....T /usr/bin/ssh
S.5....T /usr/bin/ssh-add
S.5....T /usr/bin/ssh-agent
S.5....T /usr/bin/scp
S.5....T /usr/bin/ssh-keygen
......G. /usr/bin/locate
......G. /usr/bin/updatedb
S.5....T /usr/sbin/tcpd
(Note even sure exactly what command he obtained this info with. RPM with an argument or 2?)
Now, I installed ssh on the server last week so I think that part is me. Problem is that I'm not sure whether the other changes are legitimate hacks or changed due to file dependencies involved in the ssh install.
Anyone have any idea? I'm not really sure why actual changes to these files would permanenetly affect Sendmail and FTP authentication (that went down too) Anyone's 2 cents would be greatly appreciated.
:eek:
Sendmail died on our primary web server and our server provider is saying that its been compromised. He's put the following forth as proof:
SM5....T /bin/ps
SM5....T /usr/bin/top
.M...... /usr/bin/crontab
S.5..UGT /usr/bin/bzip2
S.5....T c /sbin/ifup
missing /usr/bin/wget
S.5..UGT /usr/bin/ncftpput
S.5....T /bin/netstat
S.5....T /sbin/ifconfig
SM5....T /usr/bin/ssh
S.5....T /usr/bin/ssh-add
S.5....T /usr/bin/ssh-agent
S.5....T /usr/bin/scp
S.5....T /usr/bin/ssh-keygen
......G. /usr/bin/locate
......G. /usr/bin/updatedb
S.5....T /usr/sbin/tcpd
(Note even sure exactly what command he obtained this info with. RPM with an argument or 2?)
Now, I installed ssh on the server last week so I think that part is me. Problem is that I'm not sure whether the other changes are legitimate hacks or changed due to file dependencies involved in the ssh install.
Anyone have any idea? I'm not really sure why actual changes to these files would permanenetly affect Sendmail and FTP authentication (that went down too) Anyone's 2 cents would be greatly appreciated.
:eek: