Re: [Security] DotGeek website.

From: Date: Thu, 22 Jan 2004 02:45:39 +0000
Subject: Re: [Security] DotGeek website.
References: 1 2  Groups: php.mirrors 
Request: Send a blank email to php-mirrors+get-23104@lists.php.net to get a copy of this message
Dear All, a short update on the dotgeek.org security issue : (time referrers to GMT+1) - Following your security warning received on the 21 Jan 04 at 4:16 PM our team detected an intrusion in our previous dotgeek box hosted at ev1servers.net; -After a number of checks at 4:23 PM we removed a malicious code embedded in our html pages. The offensive code could have effected Microsoft IE users with a redirection to a Russian website as per your security warning; -Whilst nor the BIND and Mail server where *not* hosted on the same box affected by the intrusion at 5:23 PM we initiated the DNS switch from the compromised machine to a secondary secure server located in Switzerland; -On the same time we added a maintenance page and confirmed the problem ( via IRC ) to a php.net webmaster; -at 6:34 we had the confirmation that the server was compromised. We have now restored a safe backup and we are preparing to move dotgeek.org web content to a third server now in preparation with Slackware 9.1, LIDS and IP filters for SSH (not hosted at ev1.net and in a third secure location). For your reference : -the intruder used the "Linux kernel do_brk vma overflow exploit." , installed bind.c ("bindtty - like bindshell, but with tty") -/root contained .bash_history with entries of exploits -xntps and crond are new replaced -chkrootkit installed in /tmp The page modifications with relevant redirection to a malicious russian website occurred today after 12:00. Last night backups do not appear to include the offensive code. From the first forensic the intruded reached our server via another, probably compromised, ev1servers.net compromised machine. Thanks for your time and support. I will write back as soon as the transfer is finalised. Many thanks to Korkman, Negora and Mihai for the valuable help and preliminary forensic. Regards David Costa Dotgeek.org

« previous php.mirrors (#23104) next »