Windows 2k rootkit incident, files zipped for your pleasure.

From: Drew Weaver (drew_at_orbityl.com)
Date: 06/12/03

  • Next message: Ken Eichman: "Spoofed TCP SYNs w/Winsize 55808 (was: Help with an odd log file...)"
    To: <incidents@securityfocus.com>
    Date: Thu, 12 Jun 2003 11:57:23 -0400
    
    

        Hi, with the help or Karl Levinson I was able to detect the presence of
    a rootkit on one of my windows 2000 servers, I was able to grab the files
    and zip them, so maybe we can watch for this stuff in the future, im not
    sure if this rootkit has a particular name or what/not, you can get the
    files here:

    http://www.soul-fu.com/beenhaxxored.zip

    Thanks Karl.

    -Drew

    ----------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: Ken Eichman: "Spoofed TCP SYNs w/Winsize 55808 (was: Help with an odd log file...)"

    Relevant Pages


  • Quantcast