Auditing

From: Paulo Fragoso (paulo@nlink.com.br)
Date: 02/06/02


Date: Tue, 5 Feb 2002 22:24:24 -0200 (BRST)
From: Paulo Fragoso <paulo@nlink.com.br>
To: <freebsd-security@freebsd.org>

Hi,

We have a client which was using 4.2-RELEASE and telnetd enabled. In that
machine was running an ircd installed and started by a hacker, probaly
exploiting telnetd hole.

We have instaled 4.5-RELEASE using another HD and log_vain="YES" in the
rc.conf. Some time after that upgrade, someone try to connect in this
machine:

Connection attempt to UDP mmm.mmm.mmm.mmm:22 from hhh.hhh.hhh.hhh:1384

How can we found in the old system all mechanism to enable remotely ircd
or backdoor? Are there any rootkit which it has a backdoor at UDP port 22?

Paulo.

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Auditing
    ... exploiting telnetd hole. ... Are there any rootkit which it has a backdoor at UDP port 22? ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)
  • Re: Automated coffee to extreme
    ... coffee-machine and XP backdoor — what more could a hacker ask for?" ...
    (alt.coffee)
  • RE: Trojan injected in my Freebsd 4.1-RELEASE
    ... I want to find the way hacker injected trojan and close that backdoor. ... Simple restoring clean binaries will not help me understanding that way. ... Problem is that my box placed as colocated server far faraway from me in another country and I have no physical access to computer. ...
    (FreeBSD-Security)