Reply
 
Thread Tools Display Modes
  #1  
Old 01-26-09, 09:48 AM
wardmundy wardmundy is offline
Nerd Uno
 
Join Date: Oct 2007
Posts: 3,881
TB Rootkit Exploit Found
A user on the trixbox forums has found a rootkit exploit on his server.

Simple test:

Code:
ls -all /sbin/init.zk
Reply With Quote
  #2  
Old 01-26-09, 10:16 AM
TheShniz TheShniz is offline
Guru
 
Join Date: Nov 2007
Location: South FL, USA
Posts: 436
I admittedly try to avoid any & all things green, and only know about the most recent occurences through other forums/articles/etc... so I took a quick scan of their Open Discussion, and found at the top:

The Beginning of the End
http://www.trixbox.org/forums/trixbo...egining-end-ce

Suprisingly, many of the same people I knew & loved are still there, all in various stages of having given up. I understand 'the mob' aka 'the masses' can be dumb as sheep, but these guys are the ones 'that know' and are intimately aware. I suppose things become self-evident to people at different levels of obviousness, lol.

A very long, but interesting read... nothing different than what so many were saying this time last year I suppose.
__________________
- J
Reply With Quote
  #3  
Old 01-26-09, 02:15 PM
kevinfvc kevinfvc is offline
Senior Member
 
Join Date: Apr 2008
Posts: 101
Originally Posted by wardmundy View Post
A user on the trixbox forums has found a rootkit exploit on his server.

Simple test:

Code:
ls -all /sbin/init.zk
the trixbox link returns a page not found error for me...

For hacks, rootkits, ect, how much is truly the blame of fonality platform vs. poor network security (operator fault)? Is there something inherently more insecure in trixbox vs PiaF, Elastix, Switchvox, ect???

PiaF has done a good job being proactive on adding security features like fail2ban and setting IP Tables into the distribution, but if an operator choses to turn these features off, the system is as vulnerable as the next. Right?
Reply With Quote
  #4  
Old 01-26-09, 02:19 PM
rugby rugby is offline
Guru
 
Join Date: Nov 2007
Posts: 142
Originally Posted by wardmundy View Post
A user on the trixbox forums has found a rootkit exploit on his server.

Simple test:

Code:
ls -all /sbin/init.zk
That page is gone.
Reply With Quote
  #5  
Old 01-26-09, 02:24 PM
wardmundy wardmundy is offline
Nerd Uno
 
Join Date: Oct 2007
Posts: 3,881
Interesting. It appears the thread was deleted about the time California got to work this morning. That's one way to handle security threats, I suppose. Here's what's left of it on Google...

Rootkit Found on my Trixbox Server | trixbox

Jan 26, 2009 ... A quick Google turned up many hints that this was rootkit related. I ran rootkit hunter, but this turned up nothing. ...
www.trixbox.org/forums/trixbox-forums/open-discussion/rootkit-found-my-trixbox-server - 4 hours ago - Similar pages -

Rootkit Found on my Trixbox Server | trixbox

- 3:22pmJan 26, 2009 ... On further checking, I found evidence of the zk rootkit - eg: an init.zk file in /sbin. At this point I just started a reinstall - which took all of about 30 mins, including a config restore. Now, this server is behind a hardware firewall with no general access and the only ports open are those for SIP, RTP and IAX2. ...
www.trixbox.org/forums/trixbox-forums/open-discussion/rootkit-found-my-trixbox-server - 5 hours ago

Rootkit Found on my Trixbox Server | trixbox

- 3:22pmJan 26, 2009 ... So I get in via this and get root via vmsplice and then suddenly Bob's your uncle and the box isn't yours anymore. ...
www.trixbox.org/forums/trixbox-forums/open-discussion/rootkit-found-my-trixbox-server - 5 hours ago

Rootkit Found on my Trixbox Server | trixbox

- 3:22pmJan 26, 2009 ... SIP and IAX2 exploits are from 2007, there has been an information disclosure weakness in IAX2 too, which has been announced some days ago. ...
www.trixbox.org/forums/trixbox-forums/open-discussion/rootkit-found-my-trixbox-server - 5 hours ago

Rootkit Found on my Trixbox Server | trixbox

- 3:22pmJan 26, 2009 ... The vmsplice 'exploit' requires user rights to execute code on the box, that requires access either locally or remotely. ... aka "Skyking".
www.trixbox.org/forums/trixbox-forums/open-discussion/rootkit-found-my-trixbox-server - 5 hours ago


And then there's this result from donbusca.com:

Last edited by wardmundy : 01-26-09 at 07:26 PM.
Reply With Quote
  #6  
Old 01-26-09, 03:04 PM
The Deacon The Deacon is offline
Guru
 
Join Date: Jan 2008
Location: Napa/Sonoma
Posts: 171
Hmmm.... uh-huh... sure
Looks like most of the copies are gone from the Google cache, but here is an interesting post on the green box forum that "explains" the missing messages & other such mysteries of the universe...

http://www.trixbox.org/forums/trixbo...owntime-issues

Unbelievable.
Reply With Quote
  #7  
Old 01-27-09, 07:02 AM
jmullinix jmullinix is offline
Guru
 
Join Date: Oct 2007
Location: Epworth, Ga. 30541
Posts: 898
The pure presence of a rootkit on a user's machine should not be worthy of deleting the thread. Therefore one could only assume that the root kit got in through a known security flaw.
__________________
John Mullinix
Free Dial Plan builder for FreePBX
http://cohutta.com/npanxx.php
1-706-632-3343
sip://17066323343@qth.cohutta.org
Freenum 17066323343*790
Dundi Peers wanted in Baltimore, MD and Lake Wales, FL
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 09:02 PM.


Design by Vjacheslav Trushkin, color scheme by ColorizeIt!.
Powered by vBulletin®
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright ©2007-2008, Ward Mundy & Associates