Zucker
New Member
Hallo,
gestern habe ich von meinem Anbieter ein mail bekommen, dass mein server wohl abused wurde/wird. Daraufhin habe ich dann den Server mittels rootkithunter nach rootkits abgesucht, alle passwörter geändert, mit einer firewall eintreffende verbindungen auf den ssh port limitiert und generell einkommende verbindungen außer für geöffnete ports(Teamspeak+Minecraft) verboten und den direkten ssh-login auf den root abgeschaltet um einen BruteForce angriff zu erschweren.
Jetzt scheint es aber immernoch ungewollte verbindungen im netstat zu geben, die Frage ist wo diese herkommen, und ob die überhautp schädlich sind.
sollte ich noch etwas unternehmen?
hier ist einmal das log des rootkit hunters
[15:09:58] Running Rootkit Hunter version 1.4.0 on root
[15:09:58]
[15:09:58] Info: Start date is Wed Feb 26 15:09:58 CET 2014
[15:09:58]
[15:09:58] Checking configuration file and command-line options...
[15:09:58] Info: Detected operating system is 'Linux'
[15:09:58] Info: Found O/S name: Debian 7.4
[15:09:58] Info: Command line is /usr/bin/rkhunter -c
[15:09:58] Info: Environment shell is /bin/bash; rkhunter is using dash
[15:09:58] Info: Using configuration file '/etc/rkhunter.conf'
[15:09:58] Info: Installation directory is '/usr'
[15:09:58] Info: Using language 'en'
[15:09:58] Info: Using '/var/lib/rkhunter/db' as the database directory
[15:09:58] Info: Using '/usr/share/rkhunter/scripts' as the support script directory
[15:09:58] Info: Using '/usr/local/sbin /usr/local/bin /usr/sbin /usr/bin /sbin /bin' as the command directories
[15:09:58] Info: Using '/var/lib/rkhunter/tmp' as the temporary directory
[15:09:58] Info: No mail-on-warning address configured
[15:09:58] Info: X will be automatically detected
[15:09:58] Info: Found the 'basename' command: /usr/bin/basename
[15:09:58] Info: Found the 'diff' command: /usr/bin/diff
[15:09:58] Info: Found the 'dirname' command: /usr/bin/dirname
[15:09:58] Info: Found the 'file' command: /usr/bin/file
[15:09:58] Info: Found the 'find' command: /usr/bin/find
[15:09:58] Info: Found the 'ifconfig' command: /sbin/ifconfig
[15:09:58] Info: Found the 'ip' command: /sbin/ip
[15:09:58] Info: Found the 'ldd' command: /usr/bin/ldd
[15:09:58] Info: Found the 'lsattr' command: /usr/bin/lsattr
[15:09:58] Info: Found the 'lsmod' command: /sbin/lsmod
[15:09:58] Info: Found the 'lsof' command: /usr/bin/lsof
[15:09:58] Info: Found the 'mktemp' command: /bin/mktemp
[15:09:58] Info: Found the 'netstat' command: /bin/netstat
[15:09:58] Info: Found the 'perl' command: /usr/bin/perl
[15:09:58] Info: Found the 'pgrep' command: /usr/bin/pgrep
[15:09:58] Info: Found the 'ps' command: /bin/ps
[15:09:58] Info: Found the 'pwd' command: /bin/pwd
[15:09:58] Info: Found the 'readlink' command: /bin/readlink
[15:09:58] Info: Found the 'stat' command: /usr/bin/stat
[15:09:58] Info: Found the 'strings' command: /usr/bin/strings
[15:09:58] Info: System is not using prelinking
[15:09:58] Info: Using the '/usr/bin/sha1sum' command for the file hash checks
[15:09:58] Info: Stored hash values used hash function '/usr/bin/sha1sum'
[15:09:58] Info: Stored hash values did not use a package manager
[15:09:58] Info: The hash function field index is set to 1
[15:09:58] Info: No package manager specified: using hash function '/usr/bin/sha1sum'
[15:09:58] Info: Previous file attributes were stored
[15:09:59] Info: Enabled tests are: all
[15:09:59] Info: Disabled tests are: suspscan hidden_procs deleted_files packet_cap_apps apps
[15:09:59] Info: Found ksym file '/proc/kallsyms'
[15:09:59] Info: Using 'date' to process epoch second times.
Wäre wirklich für jede hilfe dankbar. Notfalls würde ich auch nen kompletten reset machen und den server neu aufsetzen, so viel ist da noch nicht drauf. Die Frage ist ob meine Sicherungsmaßnahmen ausreichen, oder ob ich etwas wichtiges vergessen habe.
gestern habe ich von meinem Anbieter ein mail bekommen, dass mein server wohl abused wurde/wird. Daraufhin habe ich dann den Server mittels rootkithunter nach rootkits abgesucht, alle passwörter geändert, mit einer firewall eintreffende verbindungen auf den ssh port limitiert und generell einkommende verbindungen außer für geöffnete ports(Teamspeak+Minecraft) verboten und den direkten ssh-login auf den root abgeschaltet um einen BruteForce angriff zu erschweren.
Jetzt scheint es aber immernoch ungewollte verbindungen im netstat zu geben, die Frage ist wo diese herkommen, und ob die überhautp schädlich sind.
sollte ich noch etwas unternehmen?
hier ist einmal das log des rootkit hunters
[15:09:58] Running Rootkit Hunter version 1.4.0 on root
[15:09:58]
[15:09:58] Info: Start date is Wed Feb 26 15:09:58 CET 2014
[15:09:58]
[15:09:58] Checking configuration file and command-line options...
[15:09:58] Info: Detected operating system is 'Linux'
[15:09:58] Info: Found O/S name: Debian 7.4
[15:09:58] Info: Command line is /usr/bin/rkhunter -c
[15:09:58] Info: Environment shell is /bin/bash; rkhunter is using dash
[15:09:58] Info: Using configuration file '/etc/rkhunter.conf'
[15:09:58] Info: Installation directory is '/usr'
[15:09:58] Info: Using language 'en'
[15:09:58] Info: Using '/var/lib/rkhunter/db' as the database directory
[15:09:58] Info: Using '/usr/share/rkhunter/scripts' as the support script directory
[15:09:58] Info: Using '/usr/local/sbin /usr/local/bin /usr/sbin /usr/bin /sbin /bin' as the command directories
[15:09:58] Info: Using '/var/lib/rkhunter/tmp' as the temporary directory
[15:09:58] Info: No mail-on-warning address configured
[15:09:58] Info: X will be automatically detected
[15:09:58] Info: Found the 'basename' command: /usr/bin/basename
[15:09:58] Info: Found the 'diff' command: /usr/bin/diff
[15:09:58] Info: Found the 'dirname' command: /usr/bin/dirname
[15:09:58] Info: Found the 'file' command: /usr/bin/file
[15:09:58] Info: Found the 'find' command: /usr/bin/find
[15:09:58] Info: Found the 'ifconfig' command: /sbin/ifconfig
[15:09:58] Info: Found the 'ip' command: /sbin/ip
[15:09:58] Info: Found the 'ldd' command: /usr/bin/ldd
[15:09:58] Info: Found the 'lsattr' command: /usr/bin/lsattr
[15:09:58] Info: Found the 'lsmod' command: /sbin/lsmod
[15:09:58] Info: Found the 'lsof' command: /usr/bin/lsof
[15:09:58] Info: Found the 'mktemp' command: /bin/mktemp
[15:09:58] Info: Found the 'netstat' command: /bin/netstat
[15:09:58] Info: Found the 'perl' command: /usr/bin/perl
[15:09:58] Info: Found the 'pgrep' command: /usr/bin/pgrep
[15:09:58] Info: Found the 'ps' command: /bin/ps
[15:09:58] Info: Found the 'pwd' command: /bin/pwd
[15:09:58] Info: Found the 'readlink' command: /bin/readlink
[15:09:58] Info: Found the 'stat' command: /usr/bin/stat
[15:09:58] Info: Found the 'strings' command: /usr/bin/strings
[15:09:58] Info: System is not using prelinking
[15:09:58] Info: Using the '/usr/bin/sha1sum' command for the file hash checks
[15:09:58] Info: Stored hash values used hash function '/usr/bin/sha1sum'
[15:09:58] Info: Stored hash values did not use a package manager
[15:09:58] Info: The hash function field index is set to 1
[15:09:58] Info: No package manager specified: using hash function '/usr/bin/sha1sum'
[15:09:58] Info: Previous file attributes were stored
[15:09:59] Info: Enabled tests are: all
[15:09:59] Info: Disabled tests are: suspscan hidden_procs deleted_files packet_cap_apps apps
[15:09:59] Info: Found ksym file '/proc/kallsyms'
[15:09:59] Info: Using 'date' to process epoch second times.
Wäre wirklich für jede hilfe dankbar. Notfalls würde ich auch nen kompletten reset machen und den server neu aufsetzen, so viel ist da noch nicht drauf. Die Frage ist ob meine Sicherungsmaßnahmen ausreichen, oder ob ich etwas wichtiges vergessen habe.