Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

aatawm

macrumors newbie
Original poster
Dec 15, 2006
10
0
my leopard box recently got hacked, and i'm trying to decipher what was done, and how dire my situation is.

i thought it was a trojan that maybe my gf had downloaded, but from what i can tell there have been no downloaded files, and she says she didn't download or install (or authenticate) anything.

below is a link to my file serve where i have the bash history as well as the original files (which can also be downloaded from the curl in the bash history)

so what were they trying to do?

Http://file.meyersproduction.com/botdarwin

system specs:
2.8 dual quad mac pro
web sharing
remote access (ssh)
remote management (vpn)
print sharing

firewall off

ports were not routed to my system from the internet (local ip's had changed and hadn't been corrected to reach my box from the internets)

i also have a dyndns set up that forwards to my ip.

much thanks
 
Looks like it installs an irc bot called Energymech, most likely used for ddos or spam.
 
Happened on my server

I'm running OSX Server 10.5. Same thing happened to me. I have very strict password policies, and also had a webserver running.

Did you ever figure out how it happened or what it was doing? Did you end up reimaging?
 
reimaged

i never figured out the attack vector, and ended up just reinstalling from scratch. which i was due for anyways...
 
i never figured out the attack vector, and ended up just reinstalling from scratch. which i was due for anyways...

Thanks, man, for the quick reply. I'm going to end up reinstalling anyway too. Just confused as to how it happened in the first place, especially considering there isn't much info on this (from what I'm getting on Google, etc.).
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.