Tilted Forum Project Discussion Community

Tilted Forum Project Discussion Community (https://thetfp.com/tfp/)
-   Tilted Technology (https://thetfp.com/tfp/tilted-technology/)
-   -   i'm being hacked! help! (https://thetfp.com/tfp/tilted-technology/61633-im-being-hacked-help.html)

soopafreek 07-06-2004 09:07 PM

i'm being hacked! help!
 
i've got a friend's server at my place. (i'm babysitting...)

anyway. a couple of days ago he needed to connect to it and asked me to open the SQLServer port (1433). so i do.

i come home today, browsing through the server and find the "ServUDaemon" process running, along with other malware.

i've been scouring the net trying to find a way to get rid of this thing.

i ran spybot... it detected "hellz little spy" (a keystroke logger). i fixed it, but i'm not sure if it's gone for sure.

i CAN'T kill the ServUDaemon process. it tells me i don't have the rights (even as an administrator)....

i've gone through and deleted a few of the files manually.

currently running housecall. it detected and cleaned the agobot worm. still waiting for more shit.

anyway, i'd appreciate some help. i had a shitty day and this is just more shit icing on the shit cake.

oh, i closed the sql port on my router, so hopefully it can't get past that. all other services (except http) are disabled... (the server hosts some small webpages).

Flyguy 07-06-2004 10:13 PM

Do you have backups of all your important shit? If you do then wipe the drives. Last resort I know but keep it in mind.

soopafreek 07-06-2004 10:15 PM

nothing very important, and yes, that'll be a last resort.

this is a friend's server.... its been hacked before due to him not patching (and caught the SQL Slammer worm).

i did manage to kill the ServU process via the "services.msc" panel. i deleted the .exe files associated and fucked with the configuration files (.ini) to change the cracker's passwords and shit.

it's pretty scary stuff. i guess once this shit's running, you can remotely monitor stuff via the web. you can even search out the infected machines by looking up this file:

|rwamelcdp

serv-u is apparently "legit" ftp software just used crack machines and set up all kinds of shit.

bob32 07-07-2004 04:13 AM

I used Serv-U awhile back while ftping my xbox. By setting up a server with it (or something like that), I was supposed to get better speeds. Didn't work too well so I trashed the program.

Key 07-07-2004 04:38 AM

it's impossible to determine the extent of damage that's been done. you can try and go through and patch it up as well as you can, but the problem is there's always the possibility you missed a tiny thing, and that's all it takes.

a clever hacker would put in registry entries to redo anything you do, as well as put in several backdoors and ways to access the system. anytime you reboot the machine you could be executing a sequence that will reopen the doors.

your SAFEST bet is to back everything up, and do a reinstall. that way you're sure you've gotten everything.

personally, this would be my FIRST resort. i consider myself adept at cleaning machines, but even i know that i'm not good enough to catch everything. so i know there's a likely probability i'd miss smething. i'd clean it up as best i can only if if there was a really good reason i shouldn't start from scratch.

Church 07-07-2004 05:06 AM

I don't suppose you're using a wireless lan, are you?

mikec 07-07-2004 05:41 AM

servU is an awesome FTP program, I couldn't live without it.

that said, what you figured out, killing the process through services.msc was the only way to stop the service.

my guess is that someone had a lot of skill, or someone physically got their hands on the box, because servU isn't part of any spyware/malware that I'm aware of. If you think it was, you might want to do a good deed and contact rhinosoft to let them konw what you went through.

soopafreek 07-07-2004 06:31 AM

(church) not on a wireless lan.

(mikec) i guess it would be someone with skill because no one would have physical access to the computer.

i've checked to see if the system was missing any patches... there was only one that it was lacking, the newest "fix" for the ADODB thing.

it's now fully patched.

i finished running housecall and other than picking up "agobot" as i mentioned earlier, it found nothing.

since disconnecting the machine's ftp, and sql port services, i've been checking my router logs and there seems to be this one IP that is probing every single port (i guess trying to get back in).

i've run "shield's up" at grc.com and other than port 80 being open, it says i'm fine.

ideas...?

Key 07-07-2004 07:22 AM

it doesn't actually take that much "skill" to install it. there are several trojans that will give a remote user even more control over the desktop than a local user.

back orifice and netbus come to mind. they'll let you transfer files and execute them. hell they'll let you control the mouse, open the cd-rom, record keystrokes, install/uninstall programs, etc.


All times are GMT -8. The time now is 03:33 AM.

Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0 PL2
© 2002-2012 Tilted Forum Project


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360