site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Uniqs:
988
Share Topic
Posting?
Post a:
Post a:
Links: ·Forum FAQ ·Attitude Adjustment ·Linux docs ·DistroWatch ·OPLM ·FreeBSD Handbook
AuthorAll Replies

maxflia

join:2003-06-30
Holly Springs, NC

Remove X Window Server

I think one of my computers has been hacked. X Window Server is installed on it. It uses port 6002 and X11:2 service. How can I uninstall this application and prevent it from reinstalling. Thank you for any help


donoreo
Premium
join:2002-05-30
North York, ON

What distro is it?


maxflia

join:2003-06-30
Holly Springs, NC

I'm not sure. How can I find out. I found out by using Look at LAN and scanning the active services. All it says is port 6002 Service X11:2 Description X Windows Server. This is on a Windows XP box and 2003 server.



donoreo
Premium
join:2002-05-30
North York, ON

You used a windows box to scan or X is running on a Windows box? If that latter, why are you asking in a Unix forum?



jdong
Eat A Beaver, Save A Tree.
Premium
join:2002-07-09
Rochester, MI
kudos:1

reply to maxflia
How do you know that it's been hacked? And it just shows something running on port 6002. Traditionally X Windows does listen on 6000+display_number but it's not necessarily (and in fact, unlikely) that it's an X windows server running on your Windows box, but rather some other service happening to listen on port 6002.
--
UbuntuForums Administrator: try Ubuntu Linux



JohnInSJ
Premium
join:2003-09-22
San Jose, CA
Reviews:
·PHONE POWER
·Comcast

reply to maxflia
1) unplug network cable - if you need it to access the box, at least unplug from internet after the switch/router

2) as root, ps lax and top - look for pscan and/or vnc processes, kill them

3) look in /tmp for the usual drop in exploits via unpatched php-based web suites (twiki and others) or any other exploit that the script kiddies love

4) reboot, see if pscan starts right up with the vnc junk, if so backup userdata, nuke system from space, rebuild (assume compromised system - safest approach)

5) if not, probably can get by with local cleanup, find attack vector and fix, etc...

What's with all the unregistered posters lately? Can Steve Ballmer really have that much free time?
--
My place : »www.schettino.us


maxflia

join:2003-06-30
Holly Springs, NC

reply to jdong
The bandwidth usage from the two computers has been very high. (100Mb an hour sometimes) I'm posting here because from what I can tell X Server is a Linux program. Does anyone know how I can verify the X Server is or is not running on my two machines?



GILXA1226
Premium,MVM
join:2000-12-29
London, OH

Are the machines running windows? If so it probably isn't an X server. Your best bet would be to open the task manager and see what was running.

Also... the X Server is a a window server, not relegated just to linux... you can get X servers for windows, but they also come with almost all unix variants.



nwrickert
sand groper
Premium,MVM
join:2004-09-04
Geneva, IL
kudos:7
Reviews:
·AT&T U-Verse

reply to maxflia
I agree with jdong See Profile, that you probably do not have an X windows server. Rather, the software causing you problems is using port 6002 because that is unlikely to conflict with anything else.

Incidently, I do have an X server on one of my XP boxes, mostly for testing. It is unlikely that a cracker would install this. Normal reason for installing is to allow you to run X windows applications on a nearby unix box, and display their output on your Windows box.

You need to find out which software is using port 6002. I think there are commands to do that, but maybe you need to install something first.
--
AT&T dsl; Westell 2200 modem/router; SuSE 10.1; firefox 2.0.0.5



jdong
Eat A Beaver, Save A Tree.
Premium
join:2002-07-09
Rochester, MI
kudos:1

reply to maxflia
Do an NMAP service scan, check active processes, install a software firewall with outbound proection that can identify what process is communicating.

I'm MORE than willing to put money on it's some P2P app using port 6002
--
UbuntuForums Administrator: try Ubuntu Linux



donoreo
Premium
join:2002-05-30
North York, ON

reply to maxflia
I bet it is some P2P software as well. What ever he used to find it is probably making an assumption that it is an X server because it is running on port 6002.


maxflia

join:2003-06-30
Holly Springs, NC

Im stumbling through NMAP right now. Its not showing 6002 but it is showing 6004 ncacn_http Microsoft Windows RPC over HTTP. I recently have taken over this network and I am trying to clean it up. Thanks for the help.



jdong
Eat A Beaver, Save A Tree.
Premium
join:2002-07-09
Rochester, MI
kudos:1

reply to maxflia
At this point, I think you should go for the Security forum -- this does not at all appear to be a X-windows/UNIX related issue, and you'd get more expertise over at the correct forum.
--
UbuntuForums Administrator: try Ubuntu Linux



donoreo
Premium
join:2002-05-30
North York, ON

reply to maxflia

said by maxflia:

Im stumbling through NMAP right now. Its not showing 6002 but it is showing 6004 ncacn_http Microsoft Windows RPC over HTTP. I recently have taken over this network and I am trying to clean it up. Thanks for the help.
That is for connecting Outlook 2003 and greater to an Exchange server.
--
The irony of common sense, it is not that common
I judge you when you use poor grammar
I cannot deny anything I did not say

Tuesday, 29-May 10:51:10 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics