Fwd: Unauthorized access to MCS machines
I want to say no, but what do the admins keep on NFS? Begin forwarded message:
From: Marc Snir <[email protected]> Subject: Re: Unauthorized access to MCS machines Date: October 14, 2011 1:47:30 AM CDT To: Ti Leggett <[email protected]> Cc: Ian Foster <[email protected]>
did you check the content of those compromised machines to make sure they did not have any sensitive, unencrypted material?
On Oct 14, 2011, at 12:47 AM, Ti Leggett wrote:
Here's an update on where we are and what we're doing. am-mac1 and am-mac2.mcs.anl.gov were both rooted this morning. These boxes were in the process of being decommissioned but had been neglected of updates for a while and had several outstanding exploitable holes. It looks like a poorly secured account at the CI was the bridge from the CI into these MCS machines.
About 1.5 hours ago we tracked down that login.ci.uchicago.edu has also been rooted. This machine seems to have used the same rootkit as the am-mac machines, but the troubling aspect about it is that it was patched to all latest about 3 weeks ago. So it *seems* we're looking at a fairly new exploit. I'm taking this machine down later tonight to do more extensive forensics to discover how it was rooted. We're also trying to track down how the attacker got on the box to begin with.
In any case, I will be sending out an announcement to the CI later explaining what has occurred. Once we have identified and patched the exploit we will be requiring all CI users to change their password. Any private keys that aren't passphrase protected will be blacklisted. At MCS we will be encouraging all users to change their password especially if they used the same password at the CI and any unprotected private keys will be blacklisted.
We may require stricter measures if we find the intrusion to be deeper or more serious than we currently are aware.
On Oct 13, 2011, at 2:39 PM, Ti Leggett wrote:
I notified Mike Papka of this this morning, but since Craig is on vacation and I'm not familiar with the procedures in this case, I overlooked informing you. My apologies.
This morning at about 4:00am there were some failed attempts on some machines in the 4th floor lab to gain elevated privileges. One of the systems staff saw the attempts, thought it looked suspicious and started investigating. By about 9:00 or so we had determined that someone had gain unauthorized access to 2 machines in the 4th floor lab. It doesn't appear that the intruder gained full elevated privileges but we are still investigating. So far it seems only the one user account and 2 lab machines are compromised. The user's account has been disabled while we continue to perform forensics. We're still investigating the full extent of the intrusion and how access was initially gained. When we have more information, I will keep you updated.
participants (1)
-
Ti Leggett