[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[cobalt-security] Cracker tools found on a RaQ 4

Hash: SHA1

Doing some work for a client, and found a set of tools called 'vanish' 
in /dev/.tty1. Looking at the source code shows this:

 Vanish.c cleans WTMP, UTMP, lastlog, messages, secure, xferlog,
 maillog, *
* warn, mail, httpd.access_log, httpd.error_log. Use your brain, check

* logs and edit accordingly
* Warning!! This programm is for educational purpouse only! I am not
* responsible to anything you do with this
* Code written for Unix like systems! Tested on SuSE-Linux 6.2 !
* Compile like: gcc vanish.c -o vanish

It needs access to the compiler to work.

I found this by running a search for all programs without a valid 
owner on the system:

find / -nouser -o -nogroup -exec ls -lF {} \;

Here's what the directory and filenames look like (sorry for the bogus 

drwxr-xr-x    5 1471     1471         1024 Oct 29 13:32 sk-1.3a/
- -rw-r--r--    1 root     500         45051 Jul  7  2002 sk-1.3a.tar.gz
- -rwxr-xr-x    1 root     500         17433 Oct 29 13:31 van*
- -rw-r--r--    1 root     500          6195 Feb 15  2000 vanish.c
- -rw-r--r--    1 root     500         45051 Jul  7  2002 
- -rw-r--r--    1 root     500          6195 Feb 15  2000 
- -rwxr-xr-x    1 root     500         17433 Oct 29 13:31 
- -rw-r--r--    1 root     500           217 Oct 29 13:32 
- -rw-r--r--    1 root     500          7236 Oct 29 13:32 
- -rw-r--r--    1 root     500          1904 Oct 29 13:32 
- -rwxr-xr-x    1 root     500         12224 Oct 29 13:32 
- -rwxr-xr-x    1 root     500         16864 Oct 29 13:32 
- -rw-r--r--    1 root     500          5908 Oct 29 13:32 
- -rw-r--r--    1 root     500          2820 Oct 29 13:32 
- -rw-r--r--    1 root     500          2976 Oct 29 13:32 
- -rw-r--r--    1 root     500         51505 Oct 29 13:32 
- -rw-r--r--    1 root     500         11548 Oct 29 13:32 
- -rw-r--r--    1 root     500          1108 Oct 29 13:32 
- -rw-r--r--    1 root     500          1084 Oct 29 13:32 
- -rw-r--r--    1 root     500          2580 Oct 29 13:32 
- -rw-r--r--    1 root     500          1708 Oct 29 13:32 
- -rw-r--r--    1 root     500          7504 Oct 29 13:32 
- -rwxr-xr-x    1 root     500         29816 Oct 29 13:32 
- -rwxr-xr-x    1 root     500          3388 Oct 29 13:32 
- -rwxr-xr-x    1 root     500         16864 Oct 29 13:32 
- -rwxr-xr-x    1 root     500         29816 Oct 29 13:32 
- -rw-r--r--    1 root     500         61671 Oct 29 13:32 

Also you might want to run a check for all setuid files and see if 
anything suspicious appears:

find / -type f -perm +6000 -exec ls -lF {} \;

I'm sending the info to the chkrootkit folks for (hopeful) inclusion 
in the next chkrootkit update...

- --
Bruce Timberlake

Version: GnuPG v1.2.1 (GNU/Linux)
