Programming Forums
User Name Password Register
 

RSS Feed
FORUM INDEX | TODAY'S POSTS | UNANSWERED THREADS | ADVANCED SEARCH

Reply
 
Thread Tools Display Modes
Old Feb 16th, 2006, 12:47 AM   #1
bigguy
Professional Programmer
 
bigguy's Avatar
 
Join Date: Sep 2005
Location: Arkansas
Posts: 296
Rep Power: 0 bigguy is an unknown quantity at this point
Send a message via AIM to bigguy Send a message via MSN to bigguy Send a message via Yahoo to bigguy
Exclamation Please Please Read - Very Big Bad Network Problems

Hey yall, I goto ICC HS. In the library we are running Windows 2000 Server or win2k3 Server. My Classroom is the only other server in the entire school. We are running SUSE10 on it. The Cliebnts on the classroom network are Win2k. The other day the main server in the library's password was changed. A computer in our classroom had two new user accounts that neither me or the other network admin added. And then Yesterday a kid was playing around and typed suse or suse.com somewhere I cant remember where cause I didnt have my NSS turned on, and it completly restarted the computer. I dont't know if he knows more then he is telling or what. But since I'm the only "known" persoin in the entire school who knows much about computers. I am being faced with being expelled. The State school computer monitoring center gave me 1 week to find out who or how it was done, or I will be expelled. Please help me. I have no idea what is going on but I think its not good. Plus we are receiving WAY more network traffic in the past month than we have in the past 4 years. Someth8ign wierd is going on and I don't want to go down for it. Please help me. Thanks
__________________
Forgiveness is the fragrance that the violet sheds on the heal that has crushed it. - Mark Twain

Destruction leads to a very rough road, but it also breeds creation.
bigguy is offline   Reply With Quote
Old Feb 16th, 2006, 2:12 AM   #2
Arevos
Programming Guru
 
Arevos's Avatar
 
Join Date: Aug 2005
Location: England
Posts: 1,499
Rep Power: 4 Arevos is on a distinguished road
Quote:
Originally Posted by bigguy
But since I'm the only "known" persoin in the entire school who knows much about computers. I am being faced with being expelled. The State school computer monitoring center gave me 1 week to find out who or how it was done, or I will be expelled.
If you're innocent, I wouldn't worry. I suspect that in your country, people are "innocent until proven guilty". Expelling students on hunches without evidence is usually not something schools can do, especially state schools.

Quote:
Originally Posted by bigguy
Please help me. I have no idea what is going on but I think its not good. Plus we are receiving WAY more network traffic in the past month than we have in the past 4 years. Someth8ign wierd is going on and I don't want to go down for it. Please help me. Thanks
Reinstall your SuSE server. Give it a different root password. If the machine has been compromised, that's the only truly safe option.
Arevos is offline   Reply With Quote
Old Feb 16th, 2006, 2:50 AM   #3
Jimbo
Battle Programmer
 
Jimbo's Avatar
 
Join Date: Feb 2006
Location: Bellevue, WA, USA
Posts: 748
Rep Power: 3 Jimbo is on a distinguished road
You might consider tracking your connections and looking for patterns in the IP addresses and ports used. Then you can decide how to deal with that. Check if you have any ports open or services running that shouldnt be. Also, if you havent already, change all the passwords and remove (or disable) the suspicious accounts. (I've not used SuSE before, and only a little bit of any flavor of Linux, and even then hardly anything administrative, so I don't know exactly how to do these... sorry)

And if you were to be expelled on such circumstancial and biased evidence, a suit against the school would probably be in order...
Jimbo is offline   Reply With Quote
Old Feb 16th, 2006, 3:50 AM   #4
Arevos
Programming Guru
 
Arevos's Avatar
 
Join Date: Aug 2005
Location: England
Posts: 1,499
Rep Power: 4 Arevos is on a distinguished road
It shouldn't be your problem to find out who did it. This presumably isn't a paying job, and unless your school wants to pay you for your time, it simply isn't worth trying to find out who compromised the machine, except to satisfy your curiousity.

If you're curious, I'd look at the logs (usually in /var/log), check the running processes (ps ax), check the bash history for root (/root/.bash_history), and anything else you can think of. But don't feel you have to. If what you say is true, and you are telling the entire story, then your school is trying to blackmail you into doing sysadmin work.

That's worth repeating. If you had nothing to do with the machine being compromised, then there is nothing the school can do to you.

Last edited by Arevos; Feb 16th, 2006 at 4:17 AM.
Arevos is offline   Reply With Quote
Old Feb 16th, 2006, 6:31 AM   #5
DaWei
Resident Grouch
 
DaWei's Avatar
 
Join Date: Jun 2005
Posts: 6,453
Rep Power: 10 DaWei is on a distinguished road
Just an echo of the others: presuming you're innocent, there's more chance of you punishing the school than vice versa. Presumably, your parents/guardian are supportive. Get up on your hind legs and don't run scared.
__________________
Abstraction doesn't make it impossible to write bad code; it makes it possible to write superior code.
Contributor's Corner: Grumpy on C++ Exceptions DaWei on Pointers
DaWei is offline   Reply With Quote
Old Feb 16th, 2006, 6:43 AM   #6
bigguy
Professional Programmer
 
bigguy's Avatar
 
Join Date: Sep 2005
Location: Arkansas
Posts: 296
Rep Power: 0 bigguy is an unknown quantity at this point
Send a message via AIM to bigguy Send a message via MSN to bigguy Send a message via Yahoo to bigguy
Thank you all very much for your ideas and suggestions. I will goto schol otday and try to figure out what is going on and let yall know. Thanks Again

Also dawei I aint a very fast runner so I wouldnt get to far.

Thanks again yall
__________________
Forgiveness is the fragrance that the violet sheds on the heal that has crushed it. - Mark Twain

Destruction leads to a very rough road, but it also breeds creation.
bigguy is offline   Reply With Quote
Old Feb 16th, 2006, 12:09 PM   #7
bigguy
Professional Programmer
 
bigguy's Avatar
 
Join Date: Sep 2005
Location: Arkansas
Posts: 296
Rep Power: 0 bigguy is an unknown quantity at this point
Send a message via AIM to bigguy Send a message via MSN to bigguy Send a message via Yahoo to bigguy
Ok, we found the problem. Someone had dled Kazaa on a couple of the computers. As for the shurdown ordeal, Im still working on that. but it looks like I'll be ok.
__________________
Forgiveness is the fragrance that the violet sheds on the heal that has crushed it. - Mark Twain

Destruction leads to a very rough road, but it also breeds creation.
bigguy is offline   Reply With Quote
Old Feb 16th, 2006, 12:17 PM   #8
Arevos
Programming Guru
 
Arevos's Avatar
 
Join Date: Aug 2005
Location: England
Posts: 1,499
Rep Power: 4 Arevos is on a distinguished road
If they were threatening to expell you over a third party installing Kazaa on their computers, then I hope now they're offering up a lot of apologies.
Arevos is offline   Reply With Quote
Old Feb 16th, 2006, 7:00 PM   #9
Dameon
Troll
 
Dameon's Avatar
 
Join Date: Apr 2005
Location: Texas
Posts: 732
Rep Power: 4 Dameon is on a distinguished road
As for the new user accounts, those were on one of the win2k machines correct? Make sure that authenticated users are not lopped into the Power Users group (the default when upgrading from NT). A power user can add and remove user accounts and reset passwords of local accounts, which would explain additional user accounts. I would assume that the machines in the room are imaged. It may behoove you to reimage the machines, make a few security enhancements (see above, but also filesystem permissions!), and reimage again with the updated image.

A few questions:
1. What role does the SuSE server play in relation to the Windows server in the library? Is it set up as an Active Directory (read: LDAP) backup/replication server? Separate altogether?
3. Do you have access to a switch/gateway between the classroom and the rest of the network? If so, majorly lock down the ports. Set a few filters to at the least block all traffic with a destination outside the school/district IP range that isn't on port 80.
4. What is your role in administering these machines? Do you have some officially delegated role in this particular classroom/school or are just being fingered for your reputation?
5. Is the increased traffic all coming from the one classroom or schoolwide?
6. Which machine rebooted, one of the clients or which of the two servers?

As for being innocent until proven guilty, tech-illiteracy of the authorities may cause problems. Be careful.
__________________
MD5(sig) = bcef75433db02e9ad9bf81d6f7c5c270
Dameon is offline   Reply With Quote
Old Feb 16th, 2006, 8:46 PM   #10
a thing
Unverified User
 
a thing's Avatar
 
Join Date: Aug 2005
Location: none
Posts: 146
Rep Power: 0 a thing is on a distinguished road
Quote:
Originally Posted by Arevos
It shouldn't be your problem to find out who did it. This presumably isn't a paying job, and unless your school wants to pay you for your time, it simply isn't worth trying to find out who compromised the machine, except to satisfy your curiousity.

If you're curious, I'd look at the logs (usually in /var/log), check the running processes (ps ax), check the bash history for root (/root/.bash_history), and anything else you can think of. But don't feel you have to. If what you say is true, and you are telling the entire story, then your school is trying to blackmail you into doing sysadmin work.

That's worth repeating. If you had nothing to do with the machine being compromised, then there is nothing the school can do to you.
http://programmingforums.org/forum/s...80&postcount=6
__________________
Warning: My posts may change (dramatically) within the first 15 minutes they're posted.
Got 'Nux?—GNU/Linux and other free software support.
It's GNU/Linux, not just Linux.
a thing is offline   Reply With Quote
Reply

Bookmarks

« Previous Thread in Forum | Next Thread in Forum »

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump




DaniWeb IT Discussion Community
All times are GMT -5. The time now is 10:29 PM.

Powered by vBulletin® Version 3.7.0, Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Copyright ©2007 DaniWeb® LLC