Overmatig dataverbruik (welk protocol)

Onderwerp: Overmatig dataverbruik (welk protocol)

  1. Overmatig dataverbruik (welk protocol)

    londoneye said:

    Overmatig dataverbruik (welk protocol)

    Ik heb een tijdje terug een outgoing DDOS gehad. SSH is dichtgespijkerd/ip-restricted. Heb zelf het gevoel dat het van Apache komt. Maar hoe kom ik erachter welk protocol hoeveel dataverkeer gebruikt? Graag met een live graph, geschiedenis is niet nodig, MRTG/SNMP vind ik niet de ideale oplossing. Hoe zouden jullie dit doen?

    En dan nog… hoe kan de server zoveel dataverkeer gebruiken via Apache… als nergens een klant is met overmatig overgebruik volgens Plesk? Moet ik het dan al buiten Apache zoeken? Ik dacht zelf aan een eventuele lekke php-site, waar exploiters misbruik van maken?

    Ntop does it :-)
    (iemand nog aanraders? waar ik meer info mee kan achterhalen, ntop is toch ideaal hiervoor?)

    En als ik de poort achterhaal... hoe weet ik welk proces het veroorzaakt?

    netstat | grep :80
    (als dat de poort is? of kan dit specifieker)
    Laatst gewijzigd door londoneye; 27/08/06 om 16:43. Reden: Automerged Doublepost
  2. Overmatig dataverbruik (welk protocol)

    D. ter Horst said:
    Het commando 'lsof' kan je meer info geven dan netstat denk ik. Verder kan ik je er niet mee helpen
  3. Overmatig dataverbruik (welk protocol)

    PimEffting said:
    Zet eens een networkanalyzer aan, zoals iptraf. Met ettercap moet je ook wel een eind kunnen komen.
    Als mijn post een mening bevat, is dat op persoonlijke titel
  4. Overmatig dataverbruik (welk protocol)

    rembrand said:
    Staan er nog bestanden in de /tmp directory ? En dan wel met ls -al kijken want als er een .FILE is staat sie je die niet met ll.

    Draaien er nog processen die je niet kent ? (ps -ef).
  5. Digiover's Avatar

    Digiover said:
    Alvorens te beginnen met commando's zoals ls, lsof, ll, ps; download en compile eerst een verse versie van een rootkit hunter (zoals chkrootkit). Uiteraard controleer je eerst de md5sums . Wanneer je systeem backdoored is, is de output van bijvoorbeeld ls, lsof of ps niet meer betrouwbaar.
    Ook de output van een reeds aanwezige chkrootkit kan niet meer betrouwbaar zijn in het geval van een rewt.
    --
    VEVIDA Services, http://www.vevida.com
  6. Overmatig dataverbruik (welk protocol)

    londoneye said:
    Code: [Bekijk]
    [root@server02 chkrootkit-0.46a]# ./chkrootkit
    ROOTDIR is `/'
    Checking `amd'... not found
    Checking `basename'... not infected
    Checking `biff'... not found
    Checking `chfn'... not infected
    Checking `chsh'... not infected
    Checking `cron'... not infected
    Checking `date'... not infected
    Checking `du'... not infected
    Checking `dirname'... not infected
    Checking `echo'... not infected
    Checking `egrep'... not infected
    Checking `env'... not infected
    Checking `find'... not infected
    Checking `fingerd'... not found
    Checking `gpm'... not infected
    Checking `grep'... not infected
    Checking `hdparm'... not infected
    Checking `su'... not infected
    Checking `ifconfig'... not infected
    Checking `inetd'... not tested
    Checking `inetdconf'... not found
    Checking `identd'... not found
    Checking `init'... not infected
    Checking `killall'... not infected
    Checking `ldsopreload'... not infected
    Checking `login'... not infected
    Checking `ls'... not infected
    Checking `lsof'... not infected
    Checking `mail'... not infected
    Checking `mingetty'... not infected
    Checking `netstat'... not infected
    Checking `named'... not infected
    Checking `passwd'... not infected
    Checking `pidof'... not infected
    Checking `pop2'... not found
    Checking `pop3'... not found
    Checking `ps'... not infected
    Checking `pstree'... not infected
    Checking `rpcinfo'... not infected
    Checking `rlogind'... not found
    Checking `rshd'... not found
    Checking `slogin'... not infected
    Checking `sendmail'... not infected
    Checking `sshd'... not infected
    Checking `syslogd'... not infected
    Checking `tar'... not infected
    Checking `tcpd'... not infected
    Checking `tcpdump'... not infected
    Checking `top'... not infected
    Checking `telnetd'... not infected
    Checking `timed'... not found
    Checking `traceroute'... not infected
    Checking `vdir'... not infected
    Checking `w'... not infected
    Checking `write'... not infected
    Checking `aliens'... no suspect files
    Searching for sniffer's logs, it may take a while... nothing found
    Searching for HiDrootkit's default dir... nothing found
    Searching for t0rn's default files and dirs... nothing found
    Searching for t0rn's v8 defaults... nothing found
    Searching for Lion Worm default files and dirs... nothing found
    Searching for RSHA's default files and dir... nothing found
    Searching for RH-Sharpe's default files... nothing found
    Searching for Ambient's rootkit (ark) default files and dirs... nothing found
    Searching for suspicious files and dirs, it may take a while...
    /usr/lib/perl5/5.8.0/i386-linux-thread-multi/.packlist
    
    Searching for LPD Worm files and dirs... nothing found
    Searching for Ramen Worm files and dirs... nothing found
    Searching for Maniac files and dirs... nothing found
    Searching for RK17 files and dirs... nothing found
    Searching for Ducoci rootkit... nothing found
    Searching for Adore Worm... nothing found
    Searching for ShitC Worm... nothing found
    Searching for Omega Worm... nothing found
    Searching for Sadmind/IIS Worm... nothing found
    Searching for MonKit... nothing found
    Searching for Showtee... nothing found
    Searching for OpticKit... nothing found
    Searching for T.R.K... nothing found
    Searching for Mithra... nothing found
    Searching for LOC rootkit... nothing found
    Searching for Romanian rootkit... nothing found
    Searching for HKRK rootkit... nothing found
    Searching for Suckit rootkit... nothing found
    Searching for Volc rootkit... nothing found
    Searching for Gold2 rootkit... nothing found
    Searching for TC2 Worm default files and dirs... nothing found
    Searching for Anonoying rootkit default files and dirs... nothing found
    Searching for ZK rootkit default files and dirs... nothing found
    Searching for ShKit rootkit default files and dirs... nothing found
    Searching for AjaKit rootkit default files and dirs... nothing found
    Searching for zaRwT rootkit default files and dirs... nothing found
    Searching for Madalin rootkit default files... nothing found
    Searching for Fu rootkit default files... nothing found
    Searching for ESRK rootkit default files... nothing found
    Searching for rootedoor... nothing found
    Searching for anomalies in shell history files... nothing found
    Checking `asp'... not infected
    Checking `bindshell'... INFECTED (PORTS:  465)
    Checking `lkm'... chkproc: nothing detected
    Checking `rexedcs'... not found
    Checking `sniffer'... eth0: PF_PACKET(/usr/bin/ntop)
    eth0:1: PF_PACKET(/usr/bin/ntop)
    Checking `w55808'... not infected
    Checking `wted'... chkwtmp: nothing deleted
    Checking `scalper'... not infected
    Checking `slapper'... not infected
    Checking `z2'... chklastlog: nothing deleted
    Checking `chkutmp'... chkutmp: nothing deleted
    [root@server02 chkrootkit-0.46a]#
    Trojan/Chrootkit-free server dus
    (BindShell en nTop zijn normaal)

    Kom niet verder mbt wat de outgoing DDOS-aanvallen vanaf de server veroorzaakt kan hebben. Weet overigens niet zeker of het een DDOS is, het gaat om excessief dataverbruik. Het gaat altijd over na het restarten van de server. Apache restart heb ik niet kunnen testen.
    Laatst gewijzigd door londoneye; 28/08/06 om 14:39.
  7. Overmatig dataverbruik (welk protocol)

    crazycoder said:
    Zou eerst eens controleren of apache niet voor proxy aan het spelen is...

    Jij denk zelf dat het door apache komt, dan is dat natuurlijk ook de eerste plaats om te gaan kijken..
  8. Overmatig dataverbruik (welk protocol)

    frvge said:
    "Checking `bindshell'... INFECTED (PORTS: 465)"?