Tilted Forum Project Discussion Community  

Go Back   Tilted Forum Project Discussion Community > Interests > Tilted Technology


 
 
LinkBack Thread Tools
Old 07-06-2004, 09:07 PM   #1 (permalink)
Psycho
 
soopafreek's Avatar
 
Location: ask your mom
i'm being hacked! help!

i've got a friend's server at my place. (i'm babysitting...)

anyway. a couple of days ago he needed to connect to it and asked me to open the SQLServer port (1433). so i do.

i come home today, browsing through the server and find the "ServUDaemon" process running, along with other malware.

i've been scouring the net trying to find a way to get rid of this thing.

i ran spybot... it detected "hellz little spy" (a keystroke logger). i fixed it, but i'm not sure if it's gone for sure.

i CAN'T kill the ServUDaemon process. it tells me i don't have the rights (even as an administrator)....

i've gone through and deleted a few of the files manually.

currently running housecall. it detected and cleaned the agobot worm. still waiting for more shit.

anyway, i'd appreciate some help. i had a shitty day and this is just more shit icing on the shit cake.

oh, i closed the sql port on my router, so hopefully it can't get past that. all other services (except http) are disabled... (the server hosts some small webpages).
__________________
aaarrrrrgggghhhh!!!!
soopafreek is offline  
Old 07-06-2004, 10:13 PM   #2 (permalink)
Banned
 
Location: Swooping down on you from above....
Do you have backups of all your important shit? If you do then wipe the drives. Last resort I know but keep it in mind.
Flyguy is offline  
Old 07-06-2004, 10:15 PM   #3 (permalink)
Psycho
 
soopafreek's Avatar
 
Location: ask your mom
nothing very important, and yes, that'll be a last resort.

this is a friend's server.... its been hacked before due to him not patching (and caught the SQL Slammer worm).

i did manage to kill the ServU process via the "services.msc" panel. i deleted the .exe files associated and fucked with the configuration files (.ini) to change the cracker's passwords and shit.

it's pretty scary stuff. i guess once this shit's running, you can remotely monitor stuff via the web. you can even search out the infected machines by looking up this file:

|rwamelcdp

serv-u is apparently "legit" ftp software just used crack machines and set up all kinds of shit.
__________________
aaarrrrrgggghhhh!!!!

Last edited by soopafreek; 07-06-2004 at 10:19 PM..
soopafreek is offline  
Old 07-07-2004, 04:13 AM   #4 (permalink)
Crazy
 
I used Serv-U awhile back while ftping my xbox. By setting up a server with it (or something like that), I was supposed to get better speeds. Didn't work too well so I trashed the program.
bob32 is offline  
Old 07-07-2004, 04:38 AM   #5 (permalink)
Key
Crazy
 
it's impossible to determine the extent of damage that's been done. you can try and go through and patch it up as well as you can, but the problem is there's always the possibility you missed a tiny thing, and that's all it takes.

a clever hacker would put in registry entries to redo anything you do, as well as put in several backdoors and ways to access the system. anytime you reboot the machine you could be executing a sequence that will reopen the doors.

your SAFEST bet is to back everything up, and do a reinstall. that way you're sure you've gotten everything.

personally, this would be my FIRST resort. i consider myself adept at cleaning machines, but even i know that i'm not good enough to catch everything. so i know there's a likely probability i'd miss smething. i'd clean it up as best i can only if if there was a really good reason i shouldn't start from scratch.
Key is offline  
Old 07-07-2004, 05:06 AM   #6 (permalink)
Tilted F*ckhead
 
Church's Avatar
 
Location: New Jersey
I don't suppose you're using a wireless lan, are you?
__________________
Through counter-intelligence, it should be possible to pinpoint potential trouble makers, and neutralize them.
Church is offline  
Old 07-07-2004, 05:41 AM   #7 (permalink)
I flopped the nutz...
 
mikec's Avatar
 
Location: Stratford, CT
servU is an awesome FTP program, I couldn't live without it.

that said, what you figured out, killing the process through services.msc was the only way to stop the service.

my guess is that someone had a lot of skill, or someone physically got their hands on the box, because servU isn't part of any spyware/malware that I'm aware of. If you think it was, you might want to do a good deed and contact rhinosoft to let them konw what you went through.
__________________
Until the 20th century, reality was everything humans could touch, smell, see, and hear. Since the initial publication of the charted electromagnetic spectrum, humans have learned that what they can touch, smell, see, and hear is less than one millionth of reality
mikec is offline  
Old 07-07-2004, 06:31 AM   #8 (permalink)
Psycho
 
soopafreek's Avatar
 
Location: ask your mom
(church) not on a wireless lan.

(mikec) i guess it would be someone with skill because no one would have physical access to the computer.

i've checked to see if the system was missing any patches... there was only one that it was lacking, the newest "fix" for the ADODB thing.

it's now fully patched.

i finished running housecall and other than picking up "agobot" as i mentioned earlier, it found nothing.

since disconnecting the machine's ftp, and sql port services, i've been checking my router logs and there seems to be this one IP that is probing every single port (i guess trying to get back in).

i've run "shield's up" at grc.com and other than port 80 being open, it says i'm fine.

ideas...?
__________________
aaarrrrrgggghhhh!!!!
soopafreek is offline  
Old 07-07-2004, 07:22 AM   #9 (permalink)
Key
Crazy
 
it doesn't actually take that much "skill" to install it. there are several trojans that will give a remote user even more control over the desktop than a local user.

back orifice and netbus come to mind. they'll let you transfer files and execute them. hell they'll let you control the mouse, open the cd-rom, record keystrokes, install/uninstall programs, etc.
Key is offline  
 

Tags
hacked


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -8. The time now is 09:19 AM.

Tilted Forum Project

Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0 PL2
© 2002-2012 Tilted Forum Project

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360