Forum Home
PC World Chat
 
Thread ID: 78409 2007-04-14 07:08:00 Why ChatF1 Is Offline Erayd (23) PC World Chat
Post ID Timestamp Content User
540979 2007-04-14 10:38:00 It comes enabled by default on Fedora, but you can choose to run it in permissive or enforcing mode. I run my system under enforcing mode and the only thing I think it *may* be interfering with is compiz and another X special effect program which refuse to run. Other than that, it quietly goes about its business un-noticed in the background.

If Bletch and Chris decide to try out SELinux, you can run it in permissive mode first and watch the logs to see how things are handled.
Jen (38)
540980 2007-04-14 11:07:00 They find it fun i guess?
The satisfaction of knowing that you have cracked something, or knowing that you are going to annoy the heck out of who ever you cracked?

Or the brag factor "i hacked into X"Lol, thats quite over estimating your importance to them. You said in the first post it was hacked as part of a DDOS attack
In essence, that makes your server just one of many minnows in a botnet that will eventually be used to take over some larger target. Its all about the bragging right of taking the big fish using the minnows, not taking the minnows themselves.
Myth (110)
540981 2007-04-14 11:18:00 Lol, thats quite over estimating your importance to them. You said in the first post it was hacked as part of a DDOS attack
In essence, that makes your server just one of many minnows in a botnet that will eventually be used to take over some larger target. Its all about the bragging right of taking the big fish using the minnows, not taking the minnows themselves.DDOS? I believe I said bruteforce password crack via ssh. Once compromised, the ChatF1 server was used as a platform to attack other machines from (using the same method).
Erayd (23)
540982 2007-04-14 11:19:00 Never mind :rolleyes: Bletch got in before me Dannz (1668)
540983 2007-04-14 12:03:00 DDOS? I believe I said bruteforce password crack via ssh. Once compromised, the ChatF1 server was used as a platform to attack other machines from (using the same method).

Never mind :rolleyes: Bletch got in before me.. and they then control your computer, and then use that computer to attack another and take control of it, and then use that computer to attack another and take control and so on and so on ..
botnet .. ddos ..
Come on guys, I thought you would have figured it out :groan:
Myth (110)
540984 2007-04-14 12:10:00 as i see it, thats using a computer to attack others. once they finished their brute force run, the deleted everything, so it doesnt look like a botnet to me... just using someone elses connection to do their hacking.

DDOS is a coordinated attack from many pcs to one. this is an attack from one pcs to many.
Dannz (1668)
540985 2007-04-14 12:12:00 I didnt realise everything had been deleted..

IN that case you are quite correct
Myth (110)
540986 2007-04-14 12:14:00 glad thats sorted then :)

Hows the server coming along bletch?
Dannz (1668)
540987 2007-04-14 12:18:00 Slowly. The old install has been nuked in case the cracker left something nasty behind (suid shells anyone?), and reinstalled with the latest version of Etch. I'm currently in the process of getting everything back up and running. Erayd (23)
540988 2007-04-15 08:25:00 Well the gateway functions of server are back, so i once again have net access...

You can thank or curse bletch later for that
:p

For those who care, i was only made aware something was wrong when i received this email:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
`This is an automatically generated message. Please do not respond to this email address.

--------------------------------------------------------------------
IMPORTANT INFORMATION ABOUT YOUR ACCOUNT
--------------------------------------------------------------------

High Speed Service: HighSpeed Service xxxxxxxx
Account number: xxxxxx

You have used 100% of your included megabytes on your TelstraClear HighSpeed Internet plan for the period to 10/05/2007.

When you do exceed your limit additional usage blocks will be charged at $2.95 per block of 2,048 megabytes, regardless of the number of megabytes you use from that block.

We will endeavour to send you another reminder email if you use additional usage blocks.

Regards

TelstraClear Internet Services Team
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

I then had a good look at the logs of my usage over the last 4 days, and yes, server moved 40GB while having conversations along the lines of..."will this password let me in?. how about this?" The fact that server moved 600MB at 07:00 when nothing but server was even on prompted a quick email to bletch, followed by me shutting server down.
personthingy (1670)
1 2 3