[Full-Disclosure] a little help needed with identifying a rootkit

From: Tobias Weisserth (tobias_at_weisserth.de)
Date: 01/13/04

  • Next message: Ka: "Re: [Full-Disclosure] Professional Groups"
    To: full-disclosure@lists.netsys.com
    Date: Tue, 13 Jan 2004 19:41:25 +0100
    
    

    Hello everybody,

    The SuSE security lists is having a little discussion about a possible
    hacked SuSE 8.2 machine. The machine is running a pre-7 PHPNuke CMS
    which could be the entryway for the injection. There is a rather big
    chance the system has been injected a script which downloaded stuff from
    here:

    http://218.234.171.84/manual/.x/

    The biggest file you can find on this machine in this directory is a
    gzipped file which probably contains a rootkit of some sort. The SuSE
    list is still trying to figure out what the rest does/is and how this
    fits into the "big picture".

    So, if you are in the mood to play around a little it would be really
    interesting what you may have say about the stuff in this directory.

    thanks a lot,
    Tobias W.

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Ka: "Re: [Full-Disclosure] Professional Groups"