Re: [Security] DotGeek website. Dotgeek is back
| From: | Mehdi | Date: | Mon, 26 Jan 2004 08:42:54 +0000 |
| Subject: | Re: [Security] DotGeek website. Dotgeek is back | ||
| References: | 1 2 3 4 5 | Groups: | php.mirrors |
| Request: | Send a blank email to php-mirrors+get-23177@lists.php.net to get a copy of this message | ||
Hi David,
I have added your news item again, it will show up quickly on our website.
Thank you for you reactivity !
didou
guru@dotgeek.org wrote:
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Dear Gabor, Mehdi, Thibaut and all, we are pleased to announce that dotgeek.org is back live on a new, completely rebuild, dedicated box running Slackware 9.1 All the necessary security measures have been implemented. You might notice from the ip that the new server is at a different location and totally separated from the old, compromised box. Whilst we do apologize for any inconvenience caused, I would appreciate your valuable support on restoring the news item at your earliest convenience. Thanks in advance for your time, patience and understanding. Best Regards David Costa for dotgeek.org On Jan 22, 2004, at 11:12 AM, Thibaut CAUTERMAN wrote:Dear DotGeek people, Many thanks for all informations you sent me on this issue. I am really glad to see you fixed found problem in a so short time and sent us detailled information. (I am now to search if exploit can be performed on our servers thanks to provided informations). I will resume my navigation on your site as soon as it will return online. May this mail be an opportunity to send our best success wishes for your initiative. Regards, Thibaut. guru@dotgeek.org wrote:-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (Darwin) iQDRAwUBQBRdtsIS8vYKprrJAQKi6QXfZftg3V7aUG7i7lvc1LHRUqwUjmI57lrH mjgZ+zn7O3RCDIp21zQmrcbFXK/zNErv1p1DS8X8dpyi1DvGsFcD1wQX1WuU77N2 7ysjE67zuCNw8E3sRcXtudXnxFXDsoT5elNZjPibM+mK8wY+7IbHa0ZAhgp1xMtn aAx79LVRoX0oaAdt95R09HavVySlg79TQneJrLDVcS4QNna4BgExka3npAMlEZUr Jm7fcD4QCLXZxBk8Ebmacia855I= =mO5t -----END PGP SIGNATURE-----Dear All, a short update on the dotgeek.org security issue : (time referrers to GMT+1) - Following your security warning received on the 21 Jan 04 at 4:16 PM our team detected an intrusion in our previous dotgeek box hosted at ev1servers.net; -After a number of checks at 4:23 PM we removed a malicious code embedded in our html pages. The offensive code could have effected Microsoft IE users with a redirection to a Russian website as per your security warning; -Whilst nor the BIND and Mail server where *not* hosted on the same box affected by the intrusion at 5:23 PM we initiated the DNS switch from the compromised machine to a secondary secure server located in Switzerland; -On the same time we added a maintenance page and confirmed the problem ( via IRC ) to a php.net webmaster; -at 6:34 we had the confirmation that the server was compromised. We have now restored a safe backup and we are preparing to move dotgeek.org web content to a third server now in preparation with Slackware 9.1, LIDS and IP filters for SSH (not hosted at ev1.net and in a third secure location). For your reference : -the intruder used the "Linux kernel do_brk vma overflow exploit." , installed bind.c ("bindtty - like bindshell, but with tty") -/root contained .bash_history with entries of exploits -xntps and crond are new replaced -chkrootkit installed in /tmp The page modifications with relevant redirection to a malicious russian website occurred today after 12:00. Last night backups do not appear to include the offensive code. From the first forensic the intruded reached our server via another, probably compromised, ev1servers.net compromised machine. Thanks for your time and support. I will write back as soon as the transfer is finalised. Many thanks to Korkman, Negora and Mihai for the valuable help and preliminary forensic. Regards David Costa Dotgeek.org