  | | | Folders Owner and permissions Changed | Folders Owner and permissions Changed 2003-06-05 - By David Booher
Back Well, by looking at the old permissions: you had write privileges open to the world and it looks like someone took advantage of that.
-- --Original Message-- -- From: Faisal [mailto:fais@(protected)] Sent: Thursday, June 05, 2003 3:42 PM To: Enigma-List@(protected) Subject: FW: Folders Owner and permissions Changed
Hi,
I just configured a web site on my RH7.2 box running apache-1 (See http://che-1.ora-code.com).3.27-1.7.2.
After defining web site about 15 minutes later I found that permissions and owner of the web site files are changed to something like this.
drwxrwxrwx 6 544 401 4096 Jun 3 16:29 admin -rwxr-xr-x 1 root root 14604 Jun 4 11:48 admin.php -rwxrwxrwx 1 544 401 2039 Sep 16 2002 auth.php drwxr-xr-x 3 root root 4096 Jun 4 13:14 backup -rwxrwxrwx 1 544 401 14976 Sep 16 2002 banners.php -rwxrwxrwx 1 544 401 2632 Sep 16 2002 footer.php -rwxrwxrwx 1 544 401 1987 Sep 16 2002 header.php drwxrwxrwx 14 544 401 4096 Jun 4 11:26 images drwxrwxrwx 2 544 401 4096 Jun 3 16:29 includes -rwxrwxrwx 1 544 401 2295 Sep 16 2002 index.php drwxrwxrwx 28 544 401 4096 Jun 4 10:48 navigation -rwxr-xr-x 1 root root 4356 Jun 4 11:23 navigation.php drwxr-xr-x 2 mysql mysql 8192 Jun 4 13:16 sql
The old files permission was like this looking at backup copy of files.
drwxrwxrwx 6 root root 4096 Jun 3 16:29 admin -rwxr-xr-x 1 root root 14604 Jun 4 11:48 admin.php -rwxrwxrwx 1 root root 2039 Sep 16 2002 auth.php -rwxrwxrwx 1 root root 4096 Sep 16 2002 backup -rwxrwxrwx 1 root root 14976 Sep 16 2002 banners.php -rwxrwxrwx 1 root root 2632 Sep 16 2002 footer.php -rwxrwxrwx 1 root root 1987 Sep 16 2002 header.php drwxrwxrwx 14 root root 4096 Jun 4 11:26 images drwxrwxrwx 2 root root 4096 Jun 3 16:29 includes -rwxrwxrwx 1 root root 2295 Sep 16 2002 index.php drwxrwxrwx 28 root root 4096 Jun 4 10:48 navigation -rwxr-xr-x 1 root root 4356 Jun 4 11:23 navigation.php drwxr-xr-x 2 mysql mysql 8192 Jun 4 13:16 sql
I also checked with my etc/passwd file for UID 544 and GID 401 both not found.
I have no ftp server running on this box neither wu-ftp or ftpdpro.
It's local company site.
Any one has any idea I am feeling compromised?
Faisal Ashraf
__ ____ ____ ____ ____ ____ ____ ____ ____ ____ enigma-list mailing list enigma-list@(protected) https://www.redhat.com/mailman/listinfo/enigma-list
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN"> <HTML> <HEAD> <META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=us-ascii"> <META NAME="Generator" CONTENT="MS Exchange Server version 5.5.2654.45"> <TITLE>RE: Folders Owner and permissions Changed</TITLE> </HEAD> <BODY>
<P><FONT SIZE=2>Well, by looking at the old permissions: you had write privileges open to the world and it looks like someone took advantage of that. </FONT></P> <BR> <BR>
<P><FONT SIZE=2>-- --Original Message-- --</FONT> <BR><FONT SIZE=2>From: Faisal [<A HREF="mailto:fais@(protected)">mailto:fais @(protected)</A>]</FONT> <BR><FONT SIZE=2>Sent: Thursday, June 05, 2003 3:42 PM</FONT> <BR><FONT SIZE=2>To: Enigma-List@(protected)</FONT> <BR><FONT SIZE=2>Subject: FW: Folders Owner and permissions Changed</FONT> </P> <BR>
<P><FONT SIZE=2>Hi,</FONT> </P>
<P><FONT SIZE=2>I just configured a web site on my RH7.2 box running</FONT> <BR><FONT SIZE=2>apache-1 (See http://che-1.ora-code.com).3.27-1.7.2.</FONT> </P>
<P><FONT SIZE=2>After defining web site about 15 minutes later I found that permissions</FONT> <BR><FONT SIZE=2>and owner of the web site files are changed to something like this. </FONT> </P>
<P><FONT SIZE=2>drwxrwxrwx 6 544   ; 401 4096 Jun 3 16 :29 admin</FONT> <BR><FONT SIZE=2>-rwxr-xr-x 1 root root 14604 Jun 4 11:48 admin .php</FONT> <BR><FONT SIZE=2>-rwxrwxrwx 1 544 401 2039 Sep 16 2002 auth.php</FONT> <BR><FONT SIZE=2>drwxr-xr-x 3 root root 4096 Jun 4 13:14 backup</FONT> <BR><FONT SIZE=2>-rwxrwxrwx 1 544 401 14976 Sep 16 2002 banners.php</FONT> <BR><FONT SIZE=2>-rwxrwxrwx 1 544 401 2632 Sep 16 2002 footer.php</FONT> <BR><FONT SIZE=2>-rwxrwxrwx 1 544 401 1987 Sep 16 2002 header.php</FONT> <BR><FONT SIZE=2>drwxrwxrwx 14 544 401 4096 Jun 4 11 :26 images</FONT> <BR><FONT SIZE=2>drwxrwxrwx 2 544 401 4096 Jun 3 16:29 includes</FONT> <BR><FONT SIZE=2>-rwxrwxrwx 1 544 401 2295 Sep 16 2002 index.php</FONT> <BR><FONT SIZE=2>drwxrwxrwx 28 544 401 4096 Jun 4 10 :48 navigation</FONT> <BR><FONT SIZE=2>-rwxr-xr-x 1 root root 4356 Jun 4 11:23 navigation.php</FONT> <BR><FONT SIZE=2>drwxr-xr-x 2 mysql mysql 8192 Jun 4 13:16 sql</FONT> </P> <BR> <BR>
<P><FONT SIZE=2>The old files permission was like this looking at backup copy of files.</FONT> </P>
<P><FONT SIZE=2>drwxrwxrwx 6 root root 4096 Jun 3 16:29 admin</FONT> <BR><FONT SIZE=2>-rwxr-xr-x 1 root root 14604 Jun 4 11:48 admin .php</FONT> <BR><FONT SIZE=2>-rwxrwxrwx 1 root root 2039 Sep 16 2002 auth.php</FONT> <BR><FONT SIZE=2>-rwxrwxrwx 1 root root 4096 Sep 16 2002 backup</FONT> <BR><FONT SIZE=2>-rwxrwxrwx 1 root root 14976 Sep 16 2002 banners .php</FONT> <BR><FONT SIZE=2>-rwxrwxrwx 1 root root 2632 Sep 16 2002 footer.php</FONT> <BR><FONT SIZE=2>-rwxrwxrwx 1 root root 1987 Sep 16 2002 header.php</FONT> <BR><FONT SIZE=2>drwxrwxrwx 14 root root 4096 Jun 4 11:26 images< /FONT> <BR><FONT SIZE=2>drwxrwxrwx 2 root root 4096 Jun 3 16:29 includes</FONT> <BR><FONT SIZE=2>-rwxrwxrwx 1 root root 2295 Sep 16 2002 index.php</FONT> <BR><FONT SIZE=2>drwxrwxrwx 28 root root 4096 Jun 4 10:48 navigation</FONT> <BR><FONT SIZE=2>-rwxr-xr-x 1 root root 4356 Jun 4 11:23 navigation.php</FONT> <BR><FONT SIZE=2>drwxr-xr-x 2 mysql mysql 8192 Jun 4 13:16 sql</FONT> </P>
<P><FONT SIZE=2>I also checked with my etc/passwd file for UID 544 and GID 401 both not</FONT> <BR><FONT SIZE=2>found.</FONT> </P>
<P><FONT SIZE=2>I have no ftp server running on this box neither wu-ftp or ftpdpro.</FONT> </P>
<P><FONT SIZE=2>It's local company site.</FONT> </P>
<P><FONT SIZE=2>Any one has any idea I am feeling compromised? </FONT> </P>
<P><FONT SIZE=2>Faisal Ashraf </FONT> </P> <BR>
<P><FONT SIZE=2>__ ____ ____ ____ ____ ____ ____ ____ ____ ____</FONT> <BR><FONT SIZE=2>enigma-list mailing list</FONT> <BR><FONT SIZE=2>enigma-list@(protected)</FONT> <BR><FONT SIZE=2><A HREF="https://www.redhat.com/mailman/listinfo/enigma-list" TARGET="_blank">https://www.redhat.com/mailman/listinfo/enigma-list</A></FONT> </P>
</BODY> </HTML>
|
|
 |