You are not logged in.

#1 2010-07-14 18:31:05

lio
Member
From: Montréal, Canada
Registered: 2009-09-13
Posts: 52

My system hacked ?

Hi all archers,

Since about a month I am suspecting that something wrong/illicit is happening on my system.

About once or twice a day, my Internet connection will almost stop responding. It will be extremely slow even to display a Google search result.

When this happens, I log into my router and notice that it's hitting the limit for maximum number of connections (which I set to 1000). When everything is fine, I usually have between 100-150 connections. Thanks to tomato firmware on the router, i can have a detail view of all those connections. heres a list to what it looked like earlier today when i copy/pasted the list. As you can see its a totally random list of destination IP/port to (from the domain names) what seems like residential ISP addresses. the source, 192.168.1.150 is my arch box.

I have gone as far as i could in identifying what is going on and mostly how to stop that from happening. My fear is that something(like a worm) is trying to make connections to a ton of places without my consent.

I do use Bittorrent occasionally, but I limit the number of outgoing connections in the client to 25 and to a source port range which does not fit with that huge amount of random connection.

I don't have much port opens on that machine, mostly ssh(with a solid password) on a non standard port, and apache mostly for posting stuff on forums and to friends.

If any security person reads this, what would be my next step in resolving that issue ?

Last edited by lio (2010-07-14 18:36:51)

Offline

#2 2010-07-14 18:45:02

ablepharus
Member
From: Berlin
Registered: 2010-05-23
Posts: 129

Re: My system hacked ?

Do you have ssh port forwarding in your router?

Offline

#3 2010-07-14 18:50:29

lio
Member
From: Montréal, Canada
Registered: 2009-09-13
Posts: 52

Re: My system hacked ?

yes , I need it often from school. but its not showing the standard port to the outside. I checked the auth.log files and they are not showing anything suspicious for ssh. all access are from my school's ip range.

Offline

#4 2010-07-14 18:51:35

Zeist
Arch Linux f@h Team Member
Registered: 2008-07-04
Posts: 532

Re: My system hacked ?

netstat -a -p

should tell you what processes your currently active connections belong to. Monitoring that should tell you what is causing all of the connections.

lsof -i

might also be interesting.

Last edited by Zeist (2010-07-14 19:00:54)


I haven't lost my mind; I have a tape back-up somewhere.
Twitter

Offline

#5 2010-07-14 18:56:16

lio
Member
From: Montréal, Canada
Registered: 2009-09-13
Posts: 52

Re: My system hacked ?

Thank you for this command, I was not aware of that usage. That should indeed provide me a lot of information. I will update this thread as to what is causing this.

Offline

#6 2010-07-14 23:48:12

eldragon
Member
From: Buenos Aires
Registered: 2008-11-18
Posts: 1,029

Re: My system hacked ?

even if you were not hacked...you should always limit the ammount of retries on ssh login attempts  (eg. 3 retries every 5 minutes).

check  fail2ban out.

Offline

#7 2010-07-15 08:42:47

moljac024
Member
From: Serbia
Registered: 2008-01-29
Posts: 2,676

Re: My system hacked ?

You should actually disable password logins and use keys.


The day Microsoft makes a product that doesn't suck, is the day they make a vacuum cleaner.
--------------------------------------------------------------------------------------------------------------
But if they tell you that I've lost my mind, maybe it's not gone just a little hard to find...

Offline

#8 2010-08-01 15:52:20

lio
Member
From: Montréal, Canada
Registered: 2009-09-13
Posts: 52

Re: My system hacked ?

Hi again,

Took me a while to get to execute the "netstat -a -p" at the proper time when my issue was happening, but I finally got it. Unfortunately it does not give the expected information hmm

im pasting the output of the command to which i add a grep with the udp and tcp keywords to get rid of all the not network related lines.

Proto Recv-Q Send-Q Local Address           Foreign Address         State       PID/Program name   
tcp        0      0 *:sunrpc                *:*                     LISTEN      1765/rpcbind        
tcp        0      0 localhost.localdom:7634 *:*                     LISTEN      1827/hddtemp        
tcp        0      0 *:2233                  *:*                     LISTEN      28969/sshd          
tcp        0      0 *:50011                 *:*                     LISTEN      29757/python        
tcp        0      0 *:50012                 *:*                     LISTEN      9237/python         
tcp        0      0 *:50014                 *:*                     LISTEN      4985/transmission   
tcp        0      0 *:673                   *:*                     LISTEN      1769/famd           
tcp        0      0 *:svn                   *:*                     LISTEN      1837/svnserve       
tcp        0      1 archbox:52083           216.168.1.27:52173      SYN_SENT    4985/transmission   
tcp        0      1 archbox:52929           128.113.153.170:53148   SYN_SENT    4985/transmission   
tcp        0      1 archbox:59104           75.55.39.205:55165      SYN_SENT    4985/transmission   
tcp        0      0 archbox:50016           AStDenis-106-1-97:53208 ESTABLISHED 9237/python         
tcp        0      1 archbox:33501           75.80.87.111:58954      SYN_SENT    4985/transmission   
tcp        0      1 archbox:51899           84.164.210.211:49155    SYN_SENT    -                   
tcp        0      1 archbox:41883           c-68-32-63-9.hsd1:28106 SYN_SENT    -                   
tcp        0      1 archbox:59437           pool-74-109-124-2:64056 SYN_SENT    -                   
tcp        0      0 archbox:50019           85.28.79.171:63598      ESTABLISHED 9237/python         
tcp        0      1 archbox:45720           213-227-221-151.s:52530 SYN_SENT    -                   
tcp        0      0 archbox:50538           baymsg1020427.gate:msnp ESTABLISHED 3363/pidgin         
tcp        0      1 archbox:50783           host-196-205-152-:16342 SYN_SENT    -                   
tcp        0      1 archbox:34655           90-227-200-18-no36:6110 SYN_SENT    -                   
tcp        0      1 archbox:39968           c-76-124-87-31.hs:28106 SYN_SENT    -                   
tcp        0      1 archbox:48489           bl11-46-179.dsl.t:54320 SYN_SENT    -                   
tcp        0      1 archbox:34698           84.153.210.78:27005     SYN_SENT    -                   
tcp        0      0 archbox:50019           85.28.79.171:63598      ESTABLISHED 9237/python         
tcp        0      0 archbox:50538           baymsg1020427.gate:msnp ESTABLISHED 3363/pidgin         
tcp        0      0 archbox:40645           85.236.110.226:ircd     ESTABLISHED 11234/irssi         
tcp        0      1 archbox:53202           76-241-37-70.ligh:52400 SYN_SENT    -                   
tcp        0      0 archbox:50016           gen92-4-82-235-9-1:6881 ESTABLISHED -                   
tcp        0      1 archbox:45601           host-196-205-152-:16342 SYN_SENT    -                   
tcp        0      1 archbox:49606           95.105.4.182.dyna:30987 SYN_SENT    -                   
tcp        0      0 archbox:50016           cac94-11-88-178-1:54568 ESTABLISHED 9237/python         
tcp        0      1 archbox:52512           71.215.180.208:48440    SYN_SENT    -                   
tcp        0      1 archbox:53019           69.14.223.194:62124     SYN_SENT    -                   
tcp        0      1 archbox:54342           net-93-148-193-67:51413 SYN_SENT    -                   
tcp        0      1 archbox:33144           75.66.168.32:57802      SYN_SENT    -                   
tcp        0      1 archbox:34747           cpe-75-81-0-123.k:42772 SYN_SENT    -                   
tcp        0      1 archbox:46387           79.182.36.47:60557      SYN_SENT    -                   
tcp        0      1 archbox:39449           ppp-70-226-168-24:20394 SYN_SENT    -                   
tcp        0      0 archbox:50012           bar06-4-82-234-18:61992 ESTABLISHED 9237/python         
tcp        0      0 archbox:50012           bar06-4-82-234-18:61992 ESTABLISHED 9237/python         
tcp        0      1 archbox:57865           p54987049.dip.t-d:61063 SYN_SENT    -                   
tcp        0      0 archbox:50012           ALyon-252-1-95-125:1698 ESTABLISHED 9237/python         
tcp        0      1 archbox:40243           artai.wheftbox.ca:61055   SYN_SENT    -                   
tcp        0      0 archbox:50018           85-218-38-111.dcl:26267 ESTABLISHED -                   
tcp        0      0 archbox:53337           gw-in-f16.1e100.n:imaps ESTABLISHED 2142/thunderbird-bi 
tcp        0      1 archbox:42684           ool-44c54ea7.dyn.:33333 SYN_SENT    -                   
tcp        0      0 archbox:50020           geek.noichi.net:47562   ESTABLISHED 9237/python         
tcp        0      0 archbox:39285           c-174-52-26-78.hs:33649 TIME_WAIT   -                   
tcp        0      1 archbox:53095           net80.195.109-181:18519 SYN_SENT    -                   
tcp        0      1 archbox:52047           p5499DA34.dip.t-d:27005 SYN_SENT    -                   
tcp        0      1 archbox:53306           216.200.119.70.cf:65000 SYN_SENT    -                   
tcp        0      0 archbox:37661           gw-in-f16.1e100.n:imaps ESTABLISHED 2142/thunderbird-bi 
tcp        0      0 archbox:50018           AOrleans-151-1-62:25739 ESTABLISHED -                   
tcp        0      0 archbox:svn             142.137.235.190:1323    ESTABLISHED 9058/svnserve       
tcp        0      1 archbox:43006           64.235.72.252:32282     SYN_SENT    -                   
tcp        0      1 archbox:58878           c-98-199-21-190.h:23965 SYN_SENT    -                   
tcp        0      1 archbox:33293           pool-98-117-151-25:6112 SYN_SENT    -                   
tcp        0      1 archbox:56050           net135.187.188-21:18519 SYN_SENT    -                   
tcp        0      1 archbox:43606           206-248-178-217.ds:1720 SYN_SENT    -                   
tcp        0      0 archbox:50012           rob92-9-88-161-11:63042 ESTABLISHED 9237/python         
tcp        0      0 archbox:34696           hosted-by.leaseweb:ircd ESTABLISHED 3338/xchat          
tcp        0      1 archbox:50020           ip-129.net-82-216:46545 SYN_SENT    -                   
tcp        0      1 archbox:50018           109.219.77-86.rev:55154 SYN_SENT    -                   
tcp        0      0 archbox:50012           4aa54-1-81-56-1-8:64051 ESTABLISHED -                   
tcp        0      0 archbox:50020           60.235.219-88.rev:59697 ESTABLISHED -                   
tcp        0      0 archbox:39643           213.143.121.183:13452   TIME_WAIT   -                   
tcp        0      1 archbox:50019           41.104.68.55:36407      SYN_SENT    -                   
tcp        0      0 archbox:60666           iw-in-f125.:xmpp-client ESTABLISHED 3363/pidgin         
tcp        0      0 archbox:50012           dan75-1-81-57-19-:52531 ESTABLISHED 9237/python         
tcp        0      0 archbox:50012           lns-bzn-30-82-253:56259 ESTABLISHED 9237/python         
tcp        0      0 archbox:50016           modemcable008.172:13706 ESTABLISHED -                   
tcp        0      0 archbox:50012           4aa54-2-82-224-86:52652 ESTABLISHED 9237/python         
tcp        0      0 localhost.localdom:7634 localhost.localdo:58981 TIME_WAIT   -                   
tcp        0      0 archbox:60617           wineasy.se.quakene:ircd ESTABLISHED 3338/xchat          
tcp        0      0 archbox:50012           19.77.68-86.rev.g:52098 ESTABLISHED -                   
tcp        0      0 archbox:50012           ADijon-551-1-74-1:51212 ESTABLISHED 9237/python         
tcp        0      0 archbox:50020           75.253.195-77.rev:31108 ESTABLISHED -                   
tcp        0      0 archbox:50012           bne75-2-82-67-188:58776 ESTABLISHED -                   
tcp        0      0 archbox:35290           S0106e0cb4e3ba147:57110 TIME_WAIT   -                   
tcp        0      0 archbox:50019           mon75-6-82-226-12:48621 ESTABLISHED -                   
tcp        0    383 archbox:59975           c-69-254-219-126.:57473 FIN_WAIT1   -                   
tcp        0      0 archbox:50020           AMontsouris-151-1:12702 ESTABLISHED -                   
tcp        0      0 archbox:50012           89-159-177-52.rev:52466 ESTABLISHED 9237/python         
tcp        0      0 archbox:50016           AToulouse-552-1-2:36500 ESTABLISHED -                   
tcp        0      0 archbox:50012           41.102.156.170:59253    ESTABLISHED -                   
tcp        0      0 archbox:50017           ANantes-556-1-165:16518 ESTABLISHED -                   
tcp        0      0 archbox:50019           bdn33-1-82-66-9-1:57079 ESTABLISHED -                   
tcp        0      0 archbox:50012           client88-85-21-59.:1303 ESTABLISHED -                   
tcp        0      0 archbox:32777           cpe-76-172-235-20:22447 TIME_WAIT   -                   
tcp        0      0 archbox:50016           85.28.79.171:63598      ESTABLISHED -                   
tcp        0      0 *:sunrpc                *:*                     LISTEN      1765/rpcbind        
tcp        0      0 *:webcache              *:*                     LISTEN      7325/java           
tcp        0      0 *:www                   *:*                     LISTEN      1852/httpd          
tcp        0      0 *:50011                 *:*                     LISTEN      29757/python        
tcp        0      0 *:50012                 *:*                     LISTEN      9237/python         
tcp        0      0 *:microsoft-ds          *:*                     LISTEN      1838/smbd           
tcp        0      0 *:50014                 *:*                     LISTEN      4985/transmission   
tcp        0      0 localhost.localdom:8005 *:*                     LISTEN      7325/java           
tcp        0      0 *:8009                  *:*                     LISTEN      7325/java           
tcp        0      0 *:netbios-ssn           *:*                     LISTEN      1838/smbd           
tcp        0      0 *:5900                  *:*                     LISTEN      21665/vino-server   
tcp        0      0 archbox:netbios-ssn     macmini:49390           ESTABLISHED 12288/smbd          
tcp        0      0 archbox:43374           105-85-252-216.ds:mysql ESTABLISHED 7325/java           
tcp        0      0 archbox:43373           105-85-252-216.ds:mysql ESTABLISHED 7325/java           
tcp        0      0 archbox:43371           105-85-252-216.ds:mysql ESTABLISHED 7325/java           
tcp        0      0 archbox:43372           105-85-252-216.ds:mysql ESTABLISHED 7325/java           
udp        0      0 archbox:54774           p1-ha-inbound-gw.me:ntp ESTABLISHED 1821/ntpd           
udp        0      0 *:sunrpc                *:*                                 1765/rpcbind        
udp        0      0 192.168.1.25:netbios-ns *:*                                 1841/nmbd           
udp        0      0 archbox:netbios-ns      *:*                                 1841/nmbd           
udp        0      0 *:netbios-ns            *:*                                 1841/nmbd           
udp        0      0 192.168.1.2:netbios-dgm *:*                                 1841/nmbd           
udp        0      0 archbox:netbios-dgm     *:*                                 1841/nmbd           
udp        0      0 *:netbios-dgm           *:*                                 1841/nmbd           
udp        0      0 *:665                   *:*                                 1765/rpcbind        
udp        0      0 archbox:57772           yike.ca:ntp             ESTABLISHED 1821/ntpd           
udp        0      0 *:sunrpc                *:*                                 1765/rpcbind        
udp        0      0 *:665                   *:*                                 1765/rpcbind

I *think* the anormal connections are those in state "SYN sent" but it seems no process can be indentified for them.

Also, since my first post, I have changed my password to an insanely secure one, restricted ssh connection to only my account, closed a few forwarded port that i was not using anymore and gave an eye to the list of user accounts on my computer to make sure that they were all legitimate.

I Welcome anyone who could help me investigate further than this.
thanks,
lio

Last edited by lio (2010-08-01 16:00:33)

Offline

#9 2010-08-01 16:05:34

Ogion
Member
From: Germany
Registered: 2007-12-11
Posts: 367

Re: My system hacked ?

Hm, you have quite a lot there.. (On my machine right now only a  running mplayer radio stream, my chat clients and a ssh connection have a connection established, a few (http server, ftp server, mpd are listening).

What are all those "python" entries? And the "java" ones?

Oh and, are you running this command as root? If not, you should, because that should make those "-" entries be actually populated with names...

Ogion


(my-dotfiles)
"People willing to trade their freedom for temporary security deserve neither and will lose both." - Benjamin Franklin
"Enlightenment is man's leaving his self-caused immaturity." - Immanuel Kant

Offline

#10 2010-08-01 16:10:46

lio
Member
From: Montréal, Canada
Registered: 2009-09-13
Posts: 52

Re: My system hacked ?

the python ones are from deluge bittorent client. they should all be in the port range of 50010-50020. The Java are from a tomcat server running as i was working on a web app when the slowdown occurred (those Java ports are not forwarded).

I am  running the command as root. I actually made the netstat command sudoable without password and created a script which is triggered with a keyboard shortcut. This to improve my reaction time to get the logging when my issue is happening.

Offline

#11 2010-08-01 16:13:39

Ogion
Member
From: Germany
Registered: 2007-12-11
Posts: 367

Re: My system hacked ?

Maybe "lsof -i" can tell you more? I'm not really sure.
Also you could check pstree and top/htop and just poke around and see if the programs/processes running seem correct to you).

Ogion


(my-dotfiles)
"People willing to trade their freedom for temporary security deserve neither and will lose both." - Benjamin Franklin
"Enlightenment is man's leaving his self-caused immaturity." - Immanuel Kant

Offline

#12 2010-08-01 16:32:34

R00KIE
Forum Fellow
From: Between a computer and a chair
Registered: 2008-09-14
Posts: 4,734

Re: My system hacked ?

Sooo ... you have transmission _and_ deluge ... working at the same time, one torrent client is enough to bring the network down, two of those will be twice as fun.

Also all those services running either as root or other users (that don't have a process name? even running netstat as root?) might also provide some insight to the problem. The number of connections seems ok for a machine running a torrent client with a few other services .... however that netbios stuff is only needed for windows (correct me if I'm wrong) so if it isn't needed I would try to get rid of it.

Also I think that limiting the port range to use in a torrent client is not the same as limiting the total number of open connections so you might want to check that too.


R00KIE
Tm90aGluZyB0byBzZWUgaGVyZSwgbW92ZSBhbG9uZy4K

Offline

#13 2010-08-01 22:24:00

Leonid.I
Member
From: Aethyr
Registered: 2009-03-22
Posts: 999

Re: My system hacked ?

If the system IS hacked, and the attacker isn't too serious, you might get something out of

ps -e u

since something unusual has to be running, right? Also, I would reinstall packages, containing coreutils, ps, netstat, ...

Last edited by Leonid.I (2010-08-01 22:24:38)


Arch Linux is more than just GNU/Linux -- it's an adventure
pkill -9 systemd

Offline

Board footer

Powered by FluxBB