listings des connections sucpectes :
Ceux-là, ça n’est pas moi :
Mar 1 20:13:26 Purgatory sshd[2177]: Accepted password for user from 204.181.200.2 port 54906 ssh2
Mar 1 20:40:34 Purgatory sshd[2193]: Accepted password for user from 79.116.45.35 port 3670 ssh2
car j’étais à ce moment déjà connecté à la machine…
Mar 2 10:37:32 Purgatory sshd[7565]: Accepted password for user from 79.116.45.217 port 3865 ssh2
Mar 4 09:11:21 Purgatory sshd[24905]: Accepted password for user from 79.116.45.152 port 1794 ssh2
c’est pas moi non plus, car à ce moment là j’étais devant aucun pc…
parmis ces quatre, je ne sais pas lequel m’a foutu le foin, car j’avais tenté de me connecté mardi en début d’après midi…
vendredi j’ai rétablit l’accès en me loggant en tant que root depuis le poste.
Mar 8 03:01:05 Purgatory sshd[9392]: Accepted password for user from 217.219.193.74 port 49010 ssh2
bon là je dormais, je suppose que c’est lui qui m’a foutu le foin aujourd’hui.
retour du script testant les md5sums:
--- MD5-ORG 2009-03-08 23:53:41.000000000 +0100
+++ MD5 2009-03-09 00:03:14.000000000 +0100
@@ -2713,7 +2713,7 @@
3c74bcbb32291e58d4e3b9a08af0631d usr/share/info/screen.info-2.gz
3c77dcdd0d04f3cf959936ad0abead56 usr/share/zoneinfo/right/America/Vancouver
3c77dcdd0d04f3cf959936ad0abead56 usr/share/zoneinfo/right/Canada/Pacific
-3c7eac8941867bf72fcc59601b286978 usr/share/locale/ru/LC_MESSAGES/mc.mo
+2c0028d6fc8bb43cb99be51621b5cd5c usr/share/locale/ru/LC_MESSAGES/mc.mo
3c838d4a47dddc48509e6ea21baa3161 usr/share/perl5/Debconf/Element/Noninteractive/Password.pm
3c873627f048fdb5c564ea687d8cace1 usr/share/man/man7/des_modes.7ssl.gz
3c8becef9c07f55cee494b95b162b8b1 lib/modules/2.6.26-1-686/kernel/sound/pci/snd-atiixp-modem.ko
retour de chkrootkit :
ROOTDIR is `/'
Checking `amd'... not found
Checking `basename'... not infected
Checking `biff'... not found
Checking `chfn'... not infected
Checking `chsh'... not infected
Checking `cron'... not infected
Checking `crontab'... not infected
Checking `date'... not infected
Checking `du'... not infected
Checking `dirname'... not infected
Checking `echo'... not infected
Checking `egrep'... not infected
Checking `env'... not infected
Checking `find'... not infected
Checking `fingerd'... not found
Checking `gpm'... not found
Checking `grep'... not infected
Checking `hdparm'... not found
Checking `su'... not infected
Checking `ifconfig'... not infected
Checking `inetd'... not infected
Checking `inetdconf'... not found
Checking `identd'... not found
Checking `init'... not infected
Checking `killall'... not found
Checking `ldsopreload'... not infected
Checking `login'... not infected
Checking `ls'... not infected
Checking `lsof'... not found
Checking `mail'... not found
Checking `mingetty'... not found
Checking `netstat'... not infected
Checking `named'... not found
Checking `passwd'... not infected
Checking `pidof'... not infected
Checking `pop2'... not found
Checking `pop3'... not found
Checking `ps'... not infected
Checking `pstree'... not found
Checking `rpcinfo'... not infected
Checking `rlogind'... not found
Checking `rshd'... not found
Checking `slogin'... not infected
Checking `sendmail'... not found
Checking `sshd'... not infected
Checking `syslogd'... not tested
Checking `tar'... not infected
Checking `tcpd'... not infected
Checking `tcpdump'... not infected
Checking `top'... not infected
Checking `telnetd'... not found
Checking `timed'... not found
Checking `traceroute'... not infected
Checking `vdir'... not infected
Checking `w'... not infected
Checking `write'... not infected
Checking `aliens'... no suspect files
Searching for sniffer's logs, it may take a while... nothing found
Searching for HiDrootkit's default dir... nothing found
Searching for t0rn's default files and dirs... nothing found
Searching for t0rn's v8 defaults... nothing found
Searching for Lion Worm default files and dirs... nothing found
Searching for RSHA's default files and dir... nothing found
Searching for RH-Sharpe's default files... nothing found
Searching for Ambient's rootkit (ark) default files and dirs... nothing found
Searching for suspicious files and dirs, it may take a while...
/lib/init/rw/.ramfs
Searching for LPD Worm files and dirs... nothing found
Searching for Ramen Worm files and dirs... nothing found
Searching for Maniac files and dirs... nothing found
Searching for RK17 files and dirs... nothing found
Searching for Ducoci rootkit... nothing found
Searching for Adore Worm... nothing found
Searching for ShitC Worm... nothing found
Searching for Omega Worm... nothing found
Searching for Sadmind/IIS Worm... nothing found
Searching for MonKit... nothing found
Searching for Showtee... nothing found
Searching for OpticKit... nothing found
Searching for T.R.K... nothing found
Searching for Mithra... nothing found
Searching for LOC rootkit... nothing found
Searching for Romanian rootkit... nothing found
Searching for Suckit rootkit... nothing found
Searching for Volc rootkit... nothing found
Searching for Gold2 rootkit... nothing found
Searching for TC2 Worm default files and dirs... nothing found
Searching for Anonoying rootkit default files and dirs... nothing found
Searching for ZK rootkit default files and dirs... nothing found
Searching for ShKit rootkit default files and dirs... nothing found
Searching for AjaKit rootkit default files and dirs... nothing found
Searching for zaRwT rootkit default files and dirs... nothing found
Searching for Madalin rootkit default files... nothing found
Searching for Fu rootkit default files... nothing found
Searching for ESRK rootkit default files... nothing found
Searching for rootedoor... nothing found
Searching for ENYELKM rootkit default files... nothing found
Searching for common ssh-scanners default files... nothing found
Searching for anomalies in shell history files... nothing found
Checking `asp'... not infected
Checking `bindshell'... not infected
Checking `lkm'... chkproc: nothing detected
chkdirs: nothing detected
Checking `rexedcs'... not found
Checking `sniffer'... lo: not promisc and no packet sniffer sockets
ath0: PACKET SNIFFER(/sbin/dhclient3[2084])
Checking `w55808'... not infected
Checking `wted'... chkwtmp: nothing deleted
Checking `scalper'... not infected
Checking `slapper'... not infected
Checking `z2'... chklastlog: nothing deleted