There’s a rootkit in the closet
void.gr
void.gr
Only after some failed attempts to download and install a new kernel, he finally did the Right Thing and shut down the server to analyze the hard disk from outside.
To everyone who encounters such a rootkit, I strongly recommend to skip this second step. If you see such a deeply integrated rootkit, shut down the computer immediately! No fiddling! Then, take out the hard disk and copy and analyze it as described in the article.
Otherwise, you’d enable the rootkit to hide its traces, and to maybe destroy some data. You don’t learn anything from that fiddling. Satisfy your curiosity only after perpetuating evidence! (i.e. after copying the hard disk’s data)
Some programs (such as login), are already statically compiled to prevent this exact thing from happening.
Static shell? Sure, sash. Also helpful when ldso or libc is busted via non-rootkit means.
$ ldd `which ldd`
not a dynamic executable
But if you audit your /etc files or the list of files in the executable directory of your web app, you also would have noticed this. It's not really undetectable, as it doesn't hide itself or the things it needs to run at all. More people check /etc once in a while than check the md5sums of their binaries. $ file `which ldd`
/usr/bin/ldd: Bourne-Again shell script text executable
It's also worth reading up on LD_TRACE_LOADED_OBJECTS and the possible exploits therein, e.g. http://news.ycombinator.com/item?id=902958If the attacker were a little more clever, they could have faked bogus ldd output too.
Why does OpenBSD not suffer from local root exploits?