Re: sequences in the auth.log

From: Devon H. O'Dell (dodell_at_sitetronics.com)
Date: 08/18/04

  • Next message: probsd org: "chfn, date, chsh INFECTED according to chkrootkit"
    Date: Wed, 18 Aug 2004 11:56:49 +0200
    To: Nikolay Pavlov <quetzal@roks.biz>, Justin <freebsd@alt-network.com>, freebsd-security@freebsd.org
    
    
    

    Nikolay Pavlov <quetzal@roks.biz> scribbled:
    > Hi, Justin
    >
    > On Tuesday, 17 August 2004 at 23:01:28 -0500, Justin wrote:
    > > I'm seeing the same thing in my log. It makes me think it is a virus because
    > > test, guest, and admin are not normal unix users.
    >
    > And I'm too. But I think that this is a some kind of Linux worm.
    > The first record in my auth.log dated on Jul 23 01:48:30
    > Nmap identificates all hosts (already more than ten) in my auth.log as
    > "Linux 2.4.0 - 2.5.20, Linux 2.4.20 (Itanium), Linux 2.4.20 - 2.4.22 w/grsecurity.org patch"
    >
    > Best regards,
    > Nikolay Pavlov.
    > _______________________________________________
    > freebsd-security@freebsd.org mailing list
    > http://lists.freebsd.org/mailman/listinfo/freebsd-security
    > To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    >

    This has recently and fully been discussed on the full-disclosure
    mailing list.

    -- 
    Kind regards,
    Devon H. O'Dell   |          dodell@sitetronics.com
    Key: 4D3D8CA7     | IRC: bofh@WhatNET thebofh@efnet
    
    



  • Next message: probsd org: "chfn, date, chsh INFECTED according to chkrootkit"

    Relevant Pages

    • Re: Junk mails (spam) filters in OE
      ... AVG from www.grisoft.com is a GOOD FREE virus program. ... is so time wasting, is there any easy way to have control ... Kind Regards ...
      (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
    • Could it happen?
      ... Make sure all your critical updates are in place. ... Scan for any virus ... ??Unplug your computer?? ... >Kind Regards ...
      (microsoft.public.windowsxp.general)
    • RE: automatically logoff .
      ... It's a well-known virus, but my feeble brain can't recall which one. ... Boot off a new AntiV CD and scan. ... "Chuck" wrote: ...
      (microsoft.public.windowsxp.security_admin)
    • Re: C:ExchSrvrmdbdataPriv.edb - VBS.Bagle.X worm.
      ... >How can I safely remove this virus without destroying ... >may data file. ...
      (microsoft.public.exchange.misc)
    • Re: Best Internet Security Programs?
      ... have a look at the reviews on my website. ... Kind Regards ... > Virus and Firewall? ...
      (alt.computer.security)