Rootkit or trojan

From: Jason Robertson (jason@ifuture.com)
Date: 04/23/02


From: "Jason Robertson" <jason@ifuture.com>
To: "'incidents@securityfocus.com'" <incidents@securityfocus.com>
Date: Mon, 22 Apr 2002 23:37:45 -0400

Okay I am wondering if anyone has seen a rootkit or trojan with the
following files (please note, I do not have access to this machine
directly, so this is only from a remote cursory view)
The OS is Sun OS 2.5 (I know I know)
First the executable

/usr/bin/xntpx was created this program seems to be some icmp utility,
which creates a large stream of ICMP traffic, the traffic we noticed
was ICMP packets > 1024 to address 0.0.0.0

Second /tmp/x which was run with xinetd /tmp/x

Third /var/adm/* had the mode 666

That was all of the information I had direct access too, though if I
remember there was also a trojan sshd using the name ssld, and modcheck
if I remember running as well

Jason

--
Jason Robertson                
Now at the Nation Research Council.

---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: VM Rootkits: The Next Big Threat? (PC Magazine)
    ... Such close relationships with hardware allow the OS to be ... they were trojan backdoored unix binary executables offering ... remote root access to the attacker that installed them. ... actual hardware and the so-called "rootkit" act as the platform for it. ...
    (alt.comp.anti-virus)
  • Re: Using only XPs firewall saves resources
    ... >> But what if you have a trojan and rootkit on your system, ... By the time you get around to scanning with those things, your private ...
    (comp.security.firewalls)
  • Re: Sony DRM Rootkit
    ... > Sony, Rootkits and Digital Rights Management Gone Too Far ... "The Register reports on the first trojan using Sony's DRM rootkit. ... reputable business magazing requesting that the businessperson verify ...
    (alt.computer.security)
  • Re: root or openssh exploited?
    ... >>I am not aware of any rootkit that would not trojan those programs first. ... > You guys aren't understanding what I'm talking about. ...
    (comp.os.linux.security)
  • Re: REC.HUMOR to be decommissioned
    ... > your choice of Trojan is more than I needed to know. ... Okay, boys, cancel the Milli-Launch and send the rowers home! ...
    (rec.humor)