The UNIX and Linux Forums  

Go Back   The UNIX and Linux Forums > Special Forums > Security
Google UNIX.COM


Security Anything involving computer security goes here.

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
Can you navigate ABOVE the home directory? patwa UNIX for Dummies Questions & Answers 4 06-13-2007 07:27 PM
home directory nokia3100 UNIX for Dummies Questions & Answers 1 05-07-2007 11:16 AM
Randomly appearing control characters in text files aakashahuja AIX 0 07-18-2006 02:26 AM
cd into home directory ~ here2learn UNIX for Dummies Questions & Answers 4 04-12-2005 06:20 AM
c++ home directory?? user666 UNIX for Dummies Questions & Answers 3 03-16-2002 05:49 PM

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 06-01-2008
Registered User
 

Join Date: Jan 2008
Posts: 7
Strange files keep appearing in my home directory

Hi everyone,

really strange files keep appearing in my home directory. I have absolutely no idea where they come from and I'm a little concerned that they could come from some kind of malware activity or Firefox exploit. I searched Google for parts of the file names but without a result. The domain mclink.net which appears in the file names seems to belong to some Spanish (?) internet provider. I am sure I never knowingly visited their web site since I don't even understand Spanish. The first set of files appeared at 2008-05-14. I moved them away and 11 days later a second set of files appeared which you can see in the output below. The concerned system is Ubuntu 8.04 with Firefox 3.0b5.

I would very much appreciate any hints on how to investigate what the origin of these files is.

Code:
$ ls -l
total 60
-rw-r--r-- 1 mo mo  429 2008-05-25 19:26 ads-format=468x30_aff_img&client=ca-pandemia@mclink.net&channel=feed&output=png&\
cuid=1c6.JOj7kT.49201101.108x81_map.shtml
-rw-r--r-- 1 mo mo  433 2008-05-25 19:26 ads-format=468x30_aff_img&client=ca-pandemia@mclink.net&channel=feed&output=png&\
cuid=1c6.JOj7kT.49201101.226x170_map.shtml
-rw-r--r-- 1 mo mo  429 2008-05-25 19:31 ads-format=468x30_aff_img&client=ca-pandemia@mclink.net&channel=feed&output=png&\
cuid=1c6.JOj7kT.55990836.108x81_map.shtml
-rw-r--r-- 1 mo mo  433 2008-05-25 19:31 ads-format=468x30_aff_img&client=ca-pandemia@mclink.net&channel=feed&output=png&\
cuid=1c6.JOj7kT.55990836.226x170_map.shtml
Reply With Quote
Forum Sponsor
  #2 (permalink)  
Old 06-01-2008
Registered User
 

Join Date: May 2006
Posts: 1
thanks............
Reply With Quote
  #3 (permalink)  
Old 06-03-2008
Registered User
 

Join Date: Jan 2008
Posts: 7
What for? Please could anyone with a clue comment on this?
Reply With Quote
  #4 (permalink)  
Old 06-05-2008
era era is online now
Herder of Useless Cats
 

Join Date: Mar 2008
Location: /there/is/only/bin/sh
Posts: 2,928
Does your Firefox history offer any hints? Can you grep for e.g. mclink.net in ~/.mozilla/firefox/*.default/Cache/* and see if you get any hits?
Reply With Quote
  #5 (permalink)  
Old 06-06-2008
Registered User
 

Join Date: Jan 2008
Posts: 7
era, thanks for the good idea! Unfortunately the only result I get is the cached page of this thread. But if I the files will appear again I will grep the Firefox cache asap.
Reply With Quote
  #6 (permalink)  
Old 06-10-2008
Registered User
 

Join Date: Jun 2008
Posts: 8
What are the files? Are they actually PNG files? If so, try to open them with a viewer. The images may clue you in to their origin.

Have you read through the "how to tell if you've been hacked" thread in this forum?
Reply With Quote
  #7 (permalink)  
Old 06-15-2008
Registered User
 

Join Date: Jan 2008
Posts: 7
Through long-term observation I found out, that miro is to blame. The files only appear after using miro and I found some relevant strings from the file names in ~/.miro/sqlitedb.
Reply With Quote
Google UNIX.COM
Reply

Tags
linux, ubuntu

Thread Tools
Display Modes




All times are GMT -7. The time now is 09:41 AM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited.
The UNIX and Linux Forums Content Copyright ©1993-2008 The CEP Blog All Rights Reserved -Ad Management by RedTyger Visit The Global Fact Book

Content Relevant URLs by vBSEO 3.2.0