Mourning the loss of our friend, WhitPhil.
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
 
Linux and Unix
Tag Cloud
access audio black screen blue screen boot bsod connection crash dell desktop drivers dvd email error excel excel 2003 firefox hard drive hardware hdmi hijackthis internet keyboard laptop malware monitor motherboard network networking outlook problem recovery router safe mode screen slow sound spyware tdlwsp.dll trojan vba video virus vista vundo windows windows 7 windows vista windows xp wireless
Search
Search for:
Tech Support Guy Forums > Operating Systems > Linux and Unix >
Was I hacked?

Tip: Click here to scan for System Errors and Optimize PC performance
[ Sponsored Link ]

Closed Thread
 
Thread Tools
evilmrhenry's Avatar
Senior Member with 106 posts.
 
Join Date: Dec 2001
17-Apr-2004, 04:07 PM #1
Was I hacked?
Debain testing.

While web browsing, I noticed the hard drive was being accessed for no apperant reason. Running System Guard, I noticed that the 'find' command was running, with the login set to "nobody". I didn't have enough permissions to end the process as a regular user, but a console window, su, and kill command ended it. Shortly after killing the process, I noticed the 'ls' command was being run.

At this time, I disconnected the computer from the Internet, and looked at the log files. auth.log looks fine, but to get a second opinion:

Code:
Apr 17 12:10:28 box sshd[542]: Server listening on 0.0.0.0 port 22.
Apr 17 12:12:26 box kdm[825]: (pam_unix) session opened for user reg_user by (uid=0)
Apr 17 12:15:53 box su[1325]: + ??? root:nobody
Apr 17 12:15:53 box su[1325]: (pam_unix) session opened for user nobody by (uid=0)
Apr 17 12:17:01 box CRON[1398]: (pam_unix) session opened for user root by (uid=0)
Apr 17 12:17:01 box CRON[1398]: (pam_unix) session closed for user root
Apr 17 12:19:02 box su[1536]: (pam_unix) authentication failure; logname= uid=1000 euid=0 tty=pts/0 ruser=reg_user rhost=  user=root
Apr 17 12:19:05 box su[1536]: pam_authenticate: Authentication failure
Apr 17 12:19:05 box su[1536]: - pts/0 reg_user:root
Apr 17 12:19:08 box su[1542]: + pts/0 reg_user:root
Apr 17 12:19:08 box su[1542]: (pam_unix) session opened for user root by (uid=1000)
Apr 17 12:19:24 box su[1615]: + ??? root:mail
Apr 17 12:19:24 box su[1615]: (pam_unix) session opened for user mail by (uid=0)
Apr 17 12:20:01 box CRON[1817]: (pam_unix) session opened for user root by (uid=0)
Apr 17 12:20:01 box CRON[1817]: (pam_unix) session closed for user root
Apr 17 12:30:01 box CRON[2427]: (pam_unix) session opened for user root by (uid=0)
Apr 17 12:30:01 box CRON[2427]: (pam_unix) session closed for user root
Apr 17 12:31:52 box su[2551]: + pts/1 reg_user:root
Apr 17 12:31:52 box su[2551]: (pam_unix) session opened for user root by (uid=1000)
Apr 17 12:31:52 box su[2553]: + pts/1 reg_user:root
Apr 17 12:31:52 box su[2553]: (pam_unix) session opened for user root by (uid=1000)
Apr 17 12:40:01 box CRON[3123]: (pam_unix) session opened for user root by (uid=0)
Apr 17 12:40:01 box CRON[3123]: (pam_unix) session closed for user root
Now, how do I determine what caused the 'find' command to be run? I'm thinking now it was just a daemon, but a log file somewhere that shows it for sure would be helpful.

(And yes, I am going to change my passwords.)
Whiteskin's Avatar
Distinguished Member with 2,051 posts.
 
Join Date: Nov 2002
Location: Alberta, Canada
Experience: Windows: Decent. Unix/Linux: Advanced +1
17-Apr-2004, 07:08 PM #2
Find is run as part of a script to update the locatedb daily by a cron job (locatedb is the database searched by the command locate (as if you couldnt guess). Locate is used to.... locate files (try it: Its very usefull...)

[edit] Oh, and it is run as nobody, because nobody is a very unpriviledged user.
__________________
emerge world_domination;
Smart Questions gentoo
Ubuntu
linux google:Shiny!
Closed Thread Bookmark and Share

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Smart Search

Find your solution!



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.

Thread Tools


You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -5. The time now is 02:18 AM.
Copyright © 1996 - 2009 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2009, Jelsoft Enterprises Ltd.
Powered by Cermak Technologies, Inc.