Dev Shed Lounge
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsOtherDev Shed Lounge

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
Stay one step ahead of the competition. Evaluate and give feedback on some of the hottest web development tools on the market today. Make your opinion heard! Click Here
  #1  
Old April 23rd, 2002, 02:24 PM
marshalleto marshalleto is offline
Junior Member
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Sep 2001
Location: virginia
Posts: 6 marshalleto User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Question crontab (seteuid: Operation Not Permitted) after I was hacked

Thank you in advance for reading...

I'm new to sys admin, and yesterday we got hacked. Don't know what they wanted or what they took... but they did screw up my crontab permissions and now root can only use crontab.

When my other users try: % crontab -e, I get this error: seteuid: Operation Not Permitted

Everything I've found in google etc. says I need a cron.allow file, which I assume is just a line delimited list of user names. Could someone give me an example of this and tell me where I should place the file (I'm running Red Hat 7.0). I tried putting this file in both /etc/cron.d/, and /var/spool/cron/, but the cron.allow file didn't do anything in either of these two directories.

Any other reasons I would get this (seteuid: Operation Not Permitted) error?

Also the hacker erased the file: /usr/lib/sa/sa1 which is run by cron.hourly. I have no idea what this file does, could anybody please give me an example.

I also noticed an entry in my /etc/shadow file which had cron down as a user, is this normal? I disabled it because I thought it might be a bogus entry and my cron jobs still run without it.

Does anybody know a possible way to get the hacker's footprint... my logs where obviously edited.

Currently our system is set up so root can log in remotely, can you tell me how to disable this?

Thank you very much for any and all advice.

Reply With Quote
  #2  
Old April 26th, 2002, 06:55 AM
M.Hirsch M.Hirsch is offline
Contributing User
Dev Shed God 1st Plane (5500 - 5999 posts)
 
Join Date: Oct 2000
Location: Back in the real world.
Posts: 5,969 M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level) 
Time spent in forums: 1 Month 1 Day 22 h 39 m 55 sec
Reputation Power: 184
since the logs have been edited, there is few chance in finding footprints.
probably the "hacker" replaced binaries or libraries, this is why the system does not work as it used to.

after an attack like this, you should
- save the whole installation to tape
- reinstall from scratch
- after this install all available security patches from your distributor.

if root-login is allowed by default from other sources than the console or ssh in your distro, switch to another. this is such a basic mistake that probably the whole distro is not worth a penny.
__________________
--
Manuel Hirsch - Linux, FreeBSD, programming, administration articles, tutorials and more.

Reply With Quote
Reply

Viewing: Dev Shed ForumsOtherDev Shed Lounge > crontab (seteuid: Operation Not Permitted) after I was hacked


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 3 hosted by Hostway