I have a Freetz router that has been hacked into using SSH.
After that, the router gets used to attack sites and/or imap accounts.
I kill all the dropbear processes with a foreign IP and hacking stops momentarily, but soon it resumes.
If I change the password it stops.
However.... After a reboot the compromised password gets restored and hacking can continue.
I know these files are involved:
/etc/shadow -> /var/tmp/shadow
/var/tmp/flash/users/shadow
My guess is that the hacker has made sure that the password stays temporary and is not written into /var/flash/freetz.
When I run passwd only the file /var/tmp/shadow changes.
The /var/tmp/flash/users/shadow stays the same. Maybe this is normal. Is it?
I am able to write the password in /var/tmp/flash/users/shadow to a fresh one using nvi.
That will permanently change my password.
The problem that I can't change the password stays however.
I can't change the password permanently with passwd.
Can someone help me to find out how the hacker compromised the router to achieve this?
When is "passwd" supposed to write the new password immediately into flash? I would think this is done immediately.
I don't think the router has been reflashed as all the addons are still there and some of those are custom.
I even monitor the flash version of the router.
After that, the router gets used to attack sites and/or imap accounts.
I kill all the dropbear processes with a foreign IP and hacking stops momentarily, but soon it resumes.
If I change the password it stops.
However.... After a reboot the compromised password gets restored and hacking can continue.
I know these files are involved:
/etc/shadow -> /var/tmp/shadow
/var/tmp/flash/users/shadow
My guess is that the hacker has made sure that the password stays temporary and is not written into /var/flash/freetz.
When I run passwd only the file /var/tmp/shadow changes.
The /var/tmp/flash/users/shadow stays the same. Maybe this is normal. Is it?
I am able to write the password in /var/tmp/flash/users/shadow to a fresh one using nvi.
That will permanently change my password.
The problem that I can't change the password stays however.
I can't change the password permanently with passwd.
Can someone help me to find out how the hacker compromised the router to achieve this?
When is "passwd" supposed to write the new password immediately into flash? I would think this is done immediately.
I don't think the router has been reflashed as all the addons are still there and some of those are custom.
I even monitor the flash version of the router.
Zuletzt bearbeitet: