Jul. 24th, 2004

solarbird: (molly-angry)
Our main mail/web server, lodestone, got rootkitted last night. Unless I've missed a security bulletin recently - which I could well have, given how things have been - it was probably a local exploit via a stolen user account. However, that's not guaranteed. (I have some suspicions about where to look; I saw a login yesterday that somewhat surprised me, but not enough for me to be alarmed. That was probably a mistake.) The rootkitting happened last night, mostly around midnight PDT.

The box has been fundamentally compromised; in addition to widespread webspace hacking, /bin and files in it have been changed. The box will need to be flattened and rebuilt. Unfortunately, this work cannot really begin until [livejournal.com profile] annathepiper gets back. We are also in the middle of trying to move, making things much more difficult.

Assume we will be down for AT LEAST four days, probably longer. During this time, our net connectivity will probably be intermittant. I may be able to get a skeleton box online to catch incoming mail before then, but no promises.

When lodestone comes back up, we will be requiring new passwords from ALL users. ALL executable files in userspace should be deleted, and either recompiled or reinstalled. These were not expert crackers; the work was sloppy; they left fingerprints everywhere, and some of their attempts to modify binaries resulted in nonexecutable files, rather than trojaned files, which is good. But that doesn't mean they were totally inept. And they were certainly trying to do as much damage and backdooring as possible, so we need to react as if they were better than they are.

If there are any former Murknet admins who think they can help/do something useful/provide advice, let me know.
solarbird: (molly-determined)
Okay, this message will serve as the header for a temporary BBS about the Murknet situation. I've postdated it so it will stay at the top of my journal, and I'll turn anonymous posting back on for a little while. Check back to this message to watch for situation updates in the reply chain.

** THIS ENTRY IS NO LONGER ADVANCE-DATED BECAUSE THAT REALLY SUCKED FOR NEW JOURNAL ENTRIES. **

Newest Status, 12:22am Tuesday: Pulled mail spools and a lot of other configuration data off of lodestone on a private LAN. The thing has all kinds of crap b0rked on it - it's drifting in space, life support is barely functional, and the warp drive is a hopeless pile of junk. Fucking Brazilians. We're having trouble getting spamassassin to invoke properly on newmoon, so no mail pointer updating yet. (V. sad.) But at least we've got mail spools so that people can get the mail that was already queued up when I pulled the plug. I've also got DNS files pulled down, and the mailman mailing list databank, so hopefully that might work again sometime this year.

Previously, on Buffy, the Vampire Slayer )

Topic: Murknet DNS
Topic: MurkMUSH accessibility
Topic: No luck yet with the new mail machine
Topic: Putting Mimi's data on Cub, updating DNS pointers
Topic: Messages I didn't think I'd see
solarbird: (Default)
This has been a hell of a weekend, hasn't it? Stupidly hot, sleeping alone (which sucks), web and mailserver rootkitted overnight which has cost me an entire day of packing, and a flat tire... which I just found out has sidewall damage so is unpatchable.

guh.

I hope Firestone is open on Sunday; otherwise Anna's going to have to take a taxi home.

EDIT: And, oh yeah. My PC's trackball cable has decided to short. This weekend RULES in that sense of SUCKING TO THE END OF TIME.

March 2026

S M T W T F S
1234567
89 1011121314
1516171819 20 21
22 2324 25262728
293031    

Most Popular Tags