Are there any Linux based Viruses ?

I have a NOWS SBE 2.5 Server (I know its no longer supported... update due in August)
Installed 3 years ago and generally just works.
2 weeks ago started getting a problem where the Internet would stop working on the network
Checked all PC's on the network with Virus checker, Replaced Router, Switch Cables, got the ISP to check ADSL line etc...
On friday discovered the problem is caused by the NOWS SBE Server - disconnect and everything works fine
Plug the NOWS back in and within minutes internet dies
Replaced Network card on the server but still the issue.
even pinging the Router from results in massive ping failures
Network tools shows 14Gb+ transmitted on ETH0
Router data flow monitor shows 2000-3000 sessions coming from the server
The Router Draytek 2960 has Danial of Service option which is on (tried it with off too)
Others have suggested a Virus might be responsible - possible ??
How does one find out whats causing this ?

Originally Posted by bhrt60
How does one find out whats causing this ?
1. Verify integrity of binaries with rpm -Va IF you have hacked binaries, you need to decide if the box is viable, or if a rebuild is better. Ensure that binaries like ps, bash, ls, top, netstat, ... are not modified. If they are, you will be re-hooking the root kit every time you do anything.
2.a. Get packet traces of the activity. This can be done via various methods. I usually want to use port mirroring + a laptop with wireshark. This records the traffic clandestinely. Otherwise using wireshark or tshark from the server itself... but that assumes its installed and working. The traces can be checked against netstat output - if they disagree, netstat may have been replaced to conceal the activity.
2.b. Observe and collect details on what binaries or scripts are active on the system using netstat -pant and top ( the press 1Hc ). Process info for a specific process is available in /proc/process_id/... You may need to be connected to the Internet for the external bad guy to activate the scripts. So its a risk to do too much sleuthing while someone may be watching. For the most part this stuff is very automated, so you are usually safe sleuthing while the bad guy is active.
At this point you show know which process is generating the traffic and maintaining the C&C bus. Web logs and so on may show the intruder starting their tools, revealing their location. So its all about identifying the means by which the scripts were dropped off and activated, and systematically blocking / removing them. You may find that the activity stops. or that the scripts re-appear 5 minutes later. These are opportunities to udnerstand how the systems is being exploited.
3. Disconnect the system from the Internet ( block inbound and outbound access ) and clean it up. You need to work backwards through logs to figure out the point of entry. This will typically be a stupid default passwords allowing direct depositing of the scripts, bugs in the web server allowing them to be exploited to drop the scripts, ...
4. Plug the holes, Patch the system, Reboot. Cross fingers.
The thing you don't want to do is attract the interest of the guy on the other end. So no "cute" challenges, the last thing you want is someone to take an interest in your system.
-- Bob

Similar Messages

  • Are there any recommendations for virus checking/removal programs for the Mac?

    Is there any recommendations for virus checking/removal programs for the iMac and MacBrook Pro running OS 10.6.7?

    as has been said, you need no AV on your Mac. more info here: Mac Virus/Malware Info.
    if, however, you exchange files with windows users on a regular basis, you might want to install ClamXav lest you pass an infected file on without realizing it.

  • Are there any web-based products out there for client project and interaction...

    Dear Web Designers,
    Is there any open source, free, php software packages out there (or web products - a doc com tool) that allows a web designer freelancer (like me) who has their own business to take in client requests or new project request descriptions and requests from anyone and allow me to respond back with an answer, a timeline, status on the project etc etc. (besides just a standard contact us form - is there any project managment tool for web designers that works well for that?)
    Andrew

    Sure.  There are lots & lots of them.  It depends on your coding skills, which scripts and databases your server supports, and how many bells & whistles you want.
    osTicket ~
    open source (free), requires PHP & MySql on your server
    http://osticket.com/features.php
    Zendesk ~
    commercial help desk system.  30 Day free trial available.
    http://www.zendesk.com/pricing
    You'll find many others on Google
    http://www.google.com/search?q=web+site+help+desk+system&ie=utf-8&oe=utf-8&aq=t&rls=org.mo zilla:en-US:official&client=firefox-a
    Nancy O.
    Alt-Web Design & Publishing
    Web | Graphics | Print | Media  Specialists 
    http://alt-web.com/
    http://twitter.com/altweb

  • Are there any other languages based on the JVM?

    are there any other languages based on the java virtual machine? woud sun allow/support that? are there any projects on this from sun or other enterprises? or some openssource projects from some enthusiastic people?

    the list counts 160 languages!Ah well... looks like I was rather wrong then :-(I'm not so sure you were. When I first started with Java I expected a number of other languages to appear that would compile to Java byte code. To me it seemed an obvious way for toolmakers such as Powersoft (PowerBuilder) to get into the Java market yet still keep customers tied to their toolset but this hasn't seemed to happen.
    There may be 160 languages/tools on that page but how many are in widespread use?
    Col

  • Are there any free safe anti-virus downloads

    are there any free safe anti-virus downloads compatible w/windows 2000

    Nothing from Adobe is free beyond the 30 day trial.  If you want free software, you'll need to look at plain HTML editors.  See link below for options.
    http://webdesign.about.com/od/windowshtmleditors/tp/free-windows-editors.htm
    Nancy O.

  • Are there any video capture devices available on Linux?

    Are there any video capture devices available on Linux?

    If you have a tv tuner card with either an s-video or av/ composite connection, then you can use that under linux with a digital video camera (dv camera). I can help if you are interested. Hope this helps!

  • Are there any Java classes  which generates UI Maps based on UI Hints

    Hi,
    I would like to know how UI Hints work and how UI Maps are generated based on UI Hints.
    Are there any java classes behind?

    Can someone help me on how to do this?

  • Are there any at-home based jobs?

    I am looking for a job that has to do with technology. I know a lot about technology but I can still learn a lot more.

    Dunkel23 wrote:
    Are there any at-home based jobs?
    On a related note:
    How Apple Gets At-Home Workers To Work

  • Are there any known viruses for Mac?

    Are there any known viruses for Mac?

    Not yet!
    You may find this User Tip on Viruses, Trojan Detection and Removal, as well as general Internet Security and Privacy, useful:
    https://discussions.apple.com/docs/DOC-2435
    (I have ClamXav set to scan incoming emails, but nothing else.)

  • Are there any information gathering tools or scripts for Sun VDI 3.1.1?

    Hi,
    Are there any information gathering tools or scripts for Sun VDI 3.1.1?
    for problem reporting or service supportting , such as
    ut_gather, a ksh based tool to collect all Sun Ray related information from a Sun Ray server.
    http://www.sun.com/bigadmin/jsp/descFile.jsp?url=descAll/ut_gather_1_4_6
    http://www.sun.com/service/gdd/index.xml
    Sun Explorer Data Collector in The Sun Services Tools Bundle (STB)
    http://www.sun.com/service/stb/index.jsp
    http://www.unix-consultants.co.uk/examples/scripts/linux/linux-explorer/
    http://www.slideshare.net/Aeroplane23/information-gathering-2
    Windows MPSreports, msinfo32
    Redhat sysreport
    Suse Siga reportconfig
    Any advice would be appreciated.
    Thanks,

    ut_gather versions are available on MOS under reference #1260464.1

  • HT3131 Are there any ventilation issues with running a macbook air in clamshell mode?

    Are there any ventilation issues with running a macbook air in clamshell mode?

    ...that makes sense to me. 
    but, why do so many MBA users (on this forum and others) claim that ventilation occurs through the keyboard?  Is this claim based on an old macbook design?
    for example, here's a related discussion (although fairly old): 
    11-08-2010, 12:16 PM
      #6 (permalink)
    SP Forsythe 
    Notebook Evangelist
    Join Date: Jul 2007 
    Location: California
    Posts: 660
    Rep Power: 14
    Re: Is it safe to use MBP with screen lid closed? Leave charge on always?
    Quote: 
    Originally Posted by tHE j0KER
    Actually I you shouldn't close the lid while running on an external screen. The keyboard of the Macbook is an air intake for the fan. Close the lid, and it could overheat.
    A common misconception of unknown origin. The intake and the exhaust for the cooling fan on the 13" MB and MBP are both located on the rear slot at the base of the hinge. In fact, you can actually see the divider that separates the intake flow from the output flow. If it were through the keyboard crevices, then an awful lot of overheats would result from people using impermeable keyboard covers, as well as Apple's warranty department would be flipping out over the Apple store carrying such covers. iSkin ProTouch FX Keyboard Cover for all MacBooks - Black Printed Keys on White - Apple Store (U.S.) 
    Does one think that Apple sells these only for use when the Notebook is off??? http://store.apple.com/us/product/TW...co=MTM3OTUwMDE Closing the lid, whilst operating the unit actually results in cooler operation due to reduction in power consumed by operating the display, which in supporting the on-board display generates heat far greater than simply powering the video port.. 
    Does one think that Apple sells these for use only when the MacBook is off? http://store.apple.com/us/product/TW...co=MTM3OTUwMDEApples direction for use is specifically for when using with an external display.
    Currently using:
    Apple MacBook Air 13" mid 2011 1.8GHz Core i7 4GB 256 GB SSD Lion & Ubuntu Linux via Fusion
    MacBook Air 11.6" late 2010 1.6 GHZ, 320M, 4GB 180 GB SSD Upgraded OWC), OS X Lion
    11-08-2010, 02:34 PM
      #7 (permalink)
    ajreynol 
    Notebook Virtuoso
    Join Date: Mar 2009 
    Location: Ann Arbor, MI
    Posts: 2,542
    Rep Power: 18
    Re: Is it safe to use MBP with screen lid closed? Leave charge on always?
    once again, I've tried a few of these keyboard covers. the Moshi keyboard cover is the ONLY one I can recommend. the others are too thick or change the keyboard experience too much.
    17" Apple MacBook Pro | i7 2720m | 160GB SSD + 750GB | 16GB | HD 6750M 1GB
    Dell 435MT | i7 920 | 10GB RAM | 7.64TB HDDs | HD 6970 | Win7+SL
    HP Elitebook 2710p Tablet PC | 1.8GHz C2D | 4GB RAM | 160GB HDD | X3100
    Apple iPhone 4 32GB | Apple iPad 64GB (Gen 3)
    Stop random laptop wakeup | 5K500.B bench data | How to Disable PowerMiser
    Disable Vaio beep when pressing volume or special keys
    11-08-2010, 03:34 PM
      #8 (permalink)
    doh123 
    Without ME its just AWESO
    Join Date: Feb 2009 
    Posts: 3,282
    Rep Power: 22
    Re: Is it safe to use MBP with screen lid closed? Leave charge on always?
    1. Closing the cover will cause more heat. This is not because of covering the keyboard very much (though it does help some heat be retained). It's mainly because of the shape of the hinge and the fact when closed it covers up the back vent a lot more. For the best cooling, it is best to have the screen open. Just run it as a dual monitor, but make the external the Primary monitor, and if you don't want to use the built in, just turn its backlight off and don't use it.
    2. The thing you plug into the wall is not a battery charger. The actual "charger" is built into the computer. It knows when to charge and when not to. If the little light on the power plug is amber, then its charging your battery. When its green, its just powering the laptop and NOT charging your battery at all.
    Mac OS X Gamer/Porter
    (We do exist!)
    Wineskin 2.5 is available!. Turn Windows apps into Mac apps for free!
    11-08-2010, 03:38 PM
      #9 (permalink)
    Wolfpup 
    Notebook Virtuoso
    Join Date: Jun 2007 
    Posts: 3,871
    Rep Power: 28
    Re: Is it safe to use MBP with screen lid closed? Leave charge on always?
    I'd leave the lid open, at least partially...yes it may be fine not doing that, but you are making heat dissipate worse, of course could even theoretically hurt the screen.
    As for the battery...well there's really only two choices, have it plugged in or not. As others mentioned, you can't overcharge the battery. It can be damaged a bit from heat, but of course the number one thing that's going to damage it is discharging it...so it's a no brainer-use it plugged in whenever possible, and try to charge it whenever possible when it's not plugged in.
    11-08-2010, 03:45 PM
      #10 (permalink)
    SP Forsythe 
    Notebook Evangelist
    Join Date: Jul 2007 
    Location: California
    Posts: 660
    Rep Power: 14
    Re: Is it safe to use MBP with screen lid closed? Leave charge on always?
    Quote: 
    Originally Posted by doh123
    1. Closing the cover will cause more heat. This is not because of covering the keyboard very much (though it does help some heat be retained). It's mainly because of the shape of the hinge and the fact when closed it covers up the back vent a lot more. For the best cooling, it is best to have the screen open. Just run it as a dual monitor, but make the external the Primary monitor, and if you don't want to use the built in, just turn its backlight off and don't use it.
    Nope. Apple would disagree with you on that one. Any "closure", which is, when compared to the amount of CFM, is insignificant. In fact, the opening size remains the same. it is only deflected at a slight angle when the lid is closed. Tilt your MBP and see. As well, shutting down the display lowers the heat being generated, even in the lower case. As I said, if it were a problem, Apple would not be selling stands designed to operate your unit in the closed position as the original poster of this thread proposes to do.
    Currently using:
    Apple MacBook Air 13" mid 2011 1.8GHz Core i7 4GB 256 GB SSD Lion & Ubuntu Linux via Fusion
    MacBook Air 11.6" late 2010 1.6 GHZ, 320M, 4GB 180 GB SSD Upgraded OWC), OS X Lion

  • I have an imac G5 with a power PC chip running os 10.5.8.  and using safari 5.0.6. are there any security threats i should be aware of?          s there a

    are there any security concerns using my PPC imac g5 running OS 10.5.8 and using Safari 5.0.6?

    You could use a browser that does not use Flash or Java, as a safety measure when visiting sites; the Safari browser has no support or recent updates. TenFourFox v 24 is fairly good, and uses later Mozilla code, is compatible with powerPC computer limitations. SeaMonkeyPPC has a similar code, but acts a little different; and there still is iCab, a good browser that will run free, but asks you get a $20. license.
    The Safari browser can be used to set a different browser up as system default, so it won't launch and open attachments or web pages; it has a setting in its preferences where you choose another browser as default. As I have four or five browsers and one dedicated to gmail (launched as signed-in, through notifier) that is how I've used the default, otherwise mine are all in the Dock.
    There is no new upgrade for Adobe Flash plugin player, etc; but the one in their site for vintage is still available at getflash player at Adobe. Most prompts online are to get you something else, even adware loads up from some not-so-clever efforts to get people to install junk. So go to the source. Someone wrote a patch that is supposed to allow a later version of Flash player to work in older 10.5.8 PPC Mac, but I have not tried it.
    The thread of security is mostly based on the user and their caution to avoid odd free software and also avoid some sites that try to get people to load cleanmymac or genieo, or other adware malware voluntarily. Those are troublesome and hard to remove, and can waste processor cycles, slow the computer & mess it up. Mostly from a browser the adware issues arise. For those you see The Safe Mac and read up on the adware removal guide, among others linked on the page: http://www.thesafemac.com/arg/
    So anyway, there is really nothing new on the face of it for obsolete OS X systems users.
    Good luck & happy computing!

  • Are there any 3rd party tools which provide Microsoft Azure IaaS diagnostics?

    Are there any 3rd party tools currently, which can be used for giving detailed diagnostics Information about the IaaS environment (like on VM's, Virtual Network etc.) in a detailed report format periodically? Please note that I am looking for any such tools
    around IaaS environment diagnostics here, and not about Application diagnostics.

    Hi Bahree,
    Microsoft does not suggest  a specific third-party product. However, we do use them, and see lots of other customers use them.
    Paraleap: Monitoring tool - http://www.paraleap.com/AzureWatch , You may browse to these site and few others to learn more, and chat with their folks directly on how they support Windows Azure.
    I see that Microsoft has published a self-help diagnostic package for running Windows-based virtual machines (VMs) in Azure IaaS and this this diagnostic package does not require opening a Support Request with
    Microsoft
    This package helps to diagnose and resolve common issues on running Windows-based VMs in Azure IaaS
    We may download the diagnostic package from Microsoft's Support Diagnostics Self-Help Portal:
    https://home.diagnostics.support.microsoft.com/SelfHelp?knowledgebaseArticleFilter=2976864
    You might want to see
    Microsoft Azure Virtual Machine Monitoring with Azure Diagnostics Extension
    Regards,
    Shirisha Paderu

  • I have upgraded to Lion Os but my Network storage (Iomega Home Media Network hard drive) does not work with Time Machine.  Are there any solution available?

    I have upgraded to Lion  OS only to find that my NAS (Iomega Home Media Network hard drive) does not work.  It tells me that it is not configured.  Are there any solutions .  Have Iomega sorted out the problem?

    Same issue here.  Based on what I can tell, iomega still has not developed a solution to the problem.  See below:
    https://iomega-na-en.custhelp.com/app/answers/detail/a_id/28327/kw/Mac%20OS%20X% 20Lion

  • Are there any guidelines on how to customize R/3 reports into BW

    Hi Everyone,
    I have quite a number of R/3 reports that is required to be converted into a BW report but I do not know what I am supposed to do.
    Are there any guidelines on how to determine if a R/3 report should be created in BW? If it should be done in BW, how do I consider if it should be reported of a cube or an ODS?
    I have been doing development for ard 3years and this is the first time I have to analyze and come up with a functional/design specs. Need help.
    If there is any documents on the guidelines, please send it to [email protected]
    Thanks.
    Regards,
    Shunhui.

    Hi Shunhui
    TABS -> here Venkat was refering to SAP education courses on BW on extraction,reporting etc.
    I am not aware if there are any guidelines given by SAP.
    I will try to help you build the approrach for this:-
    1. You should collect functional specification of R/3 report. This will include the functionality of that report, logic & calculations involved, usage of report output by end users etc.
    2. Collect technical specification- In this you create excel sheet with all fields in R/3 report with relevant details such as formulas used, calculations involved etc.
    3.Map these technical specs with BW business content. Try to see if you can get Business content datasource which will be a fit for majority of your R/3 report fields.
    4.Carry out gap analysis and end of this excerise determine how you are going to fill this gap - whether buy using Zinfoobject,routines,datasource enhancements etc.
    5.Classify the reports as Aggregate or transactional level. If it is transactional level then you need to make use of ODS.This will determine your data model in BW.
    6.Based on 5 steps mentioned above,create a design document with dataflow & data model details.
    7. Get a Sign off on functional,technical specs & design document with proposed dataflow from users and implement it.
    For templates of functional & technical specs , you can refer to blueprint section of Accelerated SAP.
    Hope this helps
    Regards
    Pradip

Maybe you are looking for