RE: chkrootkit and lkm

2003-11-26 Thread Michael Parkinson
Umm, I have the same problem. If I kill Exim and Spamassassin no hidden processes reported. Under normal load sometimes get 1-7 hidden processes. Was is a state of panic but it does appear that Exim and Spamassassin combined do create false positives. Can this be fixed? Mike Le mer

bridge firewall

2003-11-26 Thread Francisco Oliveira
Hi Brctl sends network log mesages to all system consoles. I have tried modifing syslog but it dos not stop. I don´t want see all network messages Does anybody know how I can solve it? -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL

Re: Debian servers hacked?

2003-11-26 Thread Matthijs Mohlmann
ey, Maybe some piece of advice. I run a server with the grsecurity patch on the kernel maybe that's also an option to run on the debian server(s) Maybe this is already on the server, when so, i've nothing said. Regards, Matthijs On Fri, 2003-11-21 at 13:13, Jan Wagner wrote: On Friday 21

Re: Uhm, so, what happened...?

2003-11-26 Thread Kjetil Kjernsmo
On Tuesday 25 November 2003 13:29, Alan James wrote: On Tue, 25 Nov 2003 12:09:11 +0100, Kjetil Kjernsmo [EMAIL PROTECTED] wrote: I bet there are a lot of users running around scared, not knowing what to do really... Any advices for us?? Keep your eye on

Re: Uhm, so, what happened...?

2003-11-26 Thread John Keimel
On Wed, Nov 26, 2003 at 04:46:32PM +0100, Kjetil Kjernsmo wrote: On Tuesday 25 November 2003 13:29, Alan James wrote: On Tue, 25 Nov 2003 12:09:11 +0100, Kjetil Kjernsmo [EMAIL PROTECTED] wrote: I bet there are a lot of users running around scared, not knowing what to do really...

Re: Uhm, so, what happened...?

2003-11-26 Thread Michel Verdier
[EMAIL PROTECTED] (John Keimel) a écrit : We've still got many hours of Wednesday left and if the people in charge of this are like many hackers I know, it'll be near the end of the day before anything would be posted. Which time zone ? :) 17h30 now in Paris, France -- Michel Verdier --

Re: Debian servers hacked?

2003-11-26 Thread Matt Zimmerman
On Sat, Nov 22, 2003 at 02:32:45AM -0500, George Georgalis wrote: I thought it was odd there where ~50 urgent security updates all in one evening. There weren't. Read the changelogs; these were normal bugfixes which entered stable as part of the 3.0r2 point release, whose announcement was

Re: More hacked servers?

2003-11-26 Thread Matt Zimmerman
On Tue, Nov 25, 2003 at 03:36:22PM +0100, Marcel Weber wrote: By the way: From my time at IBM I know that they have a huge anti hacker / cracker task force to defend IBM and it's costumers against attacks. It is some mixture between secret service and battleship galactica. It is not

Re: bridge firewall

2003-11-26 Thread Javier Fernndez-Sanguino Pea
On Wed, Nov 26, 2003 at 03:20:49PM +0100, Francisco Oliveira wrote: Hi Brctl sends network log mesages to all system consoles. I have tried modifing syslog but it dos not stop. I don?t want see all network messages Does anybody know how I can solve it? dmesg -n1 ? Tip: man dmesg Javi

Re: Debian servers hacked?

2003-11-26 Thread George Georgalis
On Wed, Nov 26, 2003 at 12:47:40PM -0500, Matt Zimmerman wrote: On Sat, Nov 22, 2003 at 02:32:45AM -0500, George Georgalis wrote: I thought it was odd there where ~50 urgent security updates all in one evening. There weren't. Read the changelogs; these were normal bugfixes which entered

Re: Debian servers hacked?

2003-11-26 Thread George Georgalis
On Tue, Nov 25, 2003 at 06:10:18PM -0500, Johann Koenig wrote: On Saturday November 22 at 02:32am George Georgalis [EMAIL PROTECTED] wrote: So, are these compromised updates or urgent patches? I'm guessing the former.. More likely part of 3.0r2. I've attached the message from debian-announce.

Re: Debian servers hacked?

2003-11-26 Thread Matt Zimmerman
On Wed, Nov 26, 2003 at 02:51:25PM -0500, George Georgalis wrote: I've posted 3 or 4 messages re the changes and compromise, from these I really only want to raise one point: Is there a list of what has been validated and/or restored at debian? If so I see no reason to withhold it for

Re: More hacked servers?

2003-11-26 Thread Russell Coker
On Thu, 27 Nov 2003 04:51, Matt Zimmerman [EMAIL PROTECTED] wrote: Big money does not imply big security.  Large corporations with lots of money to spend on security are compromised all the time.  Obviously, they aren't as forthcoming about it as Debian due to monetary concerns, but even those

bridge firewall

2003-11-26 Thread Francisco Oliveira
Hi Brctl sends network log mesages to all system consoles. I have tried modifing syslog but it dos not stop. I don´t want see all network messages Does anybody know how I can solve it?

Re: Debian servers hacked?

2003-11-26 Thread Matthijs Mohlmann
ey, Maybe some piece of advice. I run a server with the grsecurity patch on the kernel maybe that's also an option to run on the debian server(s) Maybe this is already on the server, when so, i've nothing said. Regards, Matthijs On Fri, 2003-11-21 at 13:13, Jan Wagner wrote: On Friday 21

Re: Debian servers hacked?

2003-11-26 Thread George Georgalis
On Wed, Nov 26, 2003 at 12:47:40PM -0500, Matt Zimmerman wrote: On Sat, Nov 22, 2003 at 02:32:45AM -0500, George Georgalis wrote: I thought it was odd there where ~50 urgent security updates all in one evening. There weren't. Read the changelogs; these were normal bugfixes which entered

Re: Uhm, so, what happened...?

2003-11-26 Thread Michel Verdier
[EMAIL PROTECTED] (John Keimel) a écrit : We've still got many hours of Wednesday left and if the people in charge of this are like many hackers I know, it'll be near the end of the day before anything would be posted. Which time zone ? :) 17h30 now in Paris, France -- Michel Verdier

Re: More hacked servers?

2003-11-26 Thread Jim Hubbard
First of all, there's no need to be defensive. I'm on your side! I certainly didn't mean to suggest that anything would be hidden - why would it? I only meant to suggest that the details of this incident (once they are all known) need to be made very public rather than being buried in a mailing

RE: chkrootkit and lkm

2003-11-26 Thread Laurent Luyckx
Le mer 26/11/2003 à 01:17, Michael Bordignon a écrit : I was just running 'chkrootkit' and came across this warning: Checking `lkm'... You have 4 process hidden for ps command Warning: Possible LKM Trojan installed I have the same problem.. I believe it's a bug in chkrootkit

Re: Debian servers hacked?

2003-11-26 Thread Matt Zimmerman
On Wed, Nov 26, 2003 at 02:51:25PM -0500, George Georgalis wrote: I've posted 3 or 4 messages re the changes and compromise, from these I really only want to raise one point: Is there a list of what has been validated and/or restored at debian? If so I see no reason to withhold it for

RE: chkrootkit and lkm

2003-11-26 Thread Michael Parkinson
Umm, I have the same problem. If I kill Exim and Spamassassin no hidden processes reported. Under normal load sometimes get 1-7 hidden processes. Was is a state of panic but it does appear that Exim and Spamassassin combined do create false positives. Can this be fixed? Mike Le mer

Re: Uhm, so, what happened...?

2003-11-26 Thread Adam D. Barratt
Michel Verdier wrote, Wednesday, November 26, 2003 4:39 PM [EMAIL PROTECTED] (John Keimel) a écrit : We've still got many hours of Wednesday left and if the people in charge of this are like many hackers I know, it'll be near the end of the day before anything would be posted. Which

Re: Debian servers hacked?

2003-11-26 Thread George Georgalis
On Tue, Nov 25, 2003 at 06:10:18PM -0500, Johann Koenig wrote: On Saturday November 22 at 02:32am George Georgalis [EMAIL PROTECTED] wrote: So, are these compromised updates or urgent patches? I'm guessing the former.. More likely part of 3.0r2. I've attached the message from debian-announce.

Re: More hacked servers?

2003-11-26 Thread Matt Zimmerman
On Tue, Nov 25, 2003 at 03:36:22PM +0100, Marcel Weber wrote: By the way: From my time at IBM I know that they have a huge anti hacker / cracker task force to defend IBM and it's costumers against attacks. It is some mixture between secret service and battleship galactica. It is not

Re: Debian servers hacked?

2003-11-26 Thread Matt Zimmerman
On Sat, Nov 22, 2003 at 02:32:45AM -0500, George Georgalis wrote: I thought it was odd there where ~50 urgent security updates all in one evening. There weren't. Read the changelogs; these were normal bugfixes which entered stable as part of the 3.0r2 point release, whose announcement was

Re: bridge firewall

2003-11-26 Thread Javier Fernández-Sanguino Peña
On Wed, Nov 26, 2003 at 03:20:49PM +0100, Francisco Oliveira wrote: Hi Brctl sends network log mesages to all system consoles. I have tried modifing syslog but it dos not stop. I don?t want see all network messages Does anybody know how I can solve it? dmesg -n1 ? Tip: man dmesg Javi

Re: Uhm, so, what happened...?

2003-11-26 Thread Kjetil Kjernsmo
On Tuesday 25 November 2003 13:29, Alan James wrote: On Tue, 25 Nov 2003 12:09:11 +0100, Kjetil Kjernsmo [EMAIL PROTECTED] wrote: I bet there are a lot of users running around scared, not knowing what to do really... Any advices for us?? Keep your eye on

Re: Uhm, so, what happened...?

2003-11-26 Thread John Keimel
On Wed, Nov 26, 2003 at 04:46:32PM +0100, Kjetil Kjernsmo wrote: On Tuesday 25 November 2003 13:29, Alan James wrote: On Tue, 25 Nov 2003 12:09:11 +0100, Kjetil Kjernsmo [EMAIL PROTECTED] wrote: I bet there are a lot of users running around scared, not knowing what to do really...