Re: Trojan found on Linux server



This seems to be some retarded irc bot.
irc server: 64.239.9.236
irc port: 3434
server password: f9dsa

-
There are 87 users and 0 services on 1 servers
1 operators online
70 unknown connections
10 channels formed
I have 87 users, 0 services and 0 servers

64.239.9.236 -> goes to some christian website running phpnuke.

If you wanna know more load up a sniffer then execute the program as a NON ROOT user wait a bit kill the proccess then look at the sniffer logs.

-- evilrabbi --

---------------------------------------------------------------------------
EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The Norwich University program offers unparalleled Infosec management
education and the case study affords you unmatched consulting experience.
Tailor your education to your own professional goals with degree
customizations including Emergency Management, Business Continuity Planning,
Computer Emergency Response Teams, and Digital Investigations.

http://www.msia.norwich.edu/secfocus
----------------------------------------------------------------------------



Relevant Pages

  • Re: java vs irc
    ... If someone logs on to an IRC server how do i tell the other users what gender the user has? ... I'd go with a custom Java client layered on top of IRC. ... As to whether your custom Java implementation will be more performant than an IRC solution you might download, ...
    (comp.lang.java.help)
  • [fw-wiz] stopping bots from phoning home
    ... It seems that the majority of bots connect to an IRC server in order to ... get their instructions and some spyware is starting to do the same. ... vast majority of security truisms that are stated repeatedly on this list. ...
    (Firewall-Wizards)
  • Re: Easy IRC client/server for linux? (for kids, edubuntu, blah blah)
    ... What I would like to do is to install some IRC server on my ... As for IRC clients, I use the fantastic ...
    (comp.os.linux.misc)
  • Re: [fw-wiz] stopping bots from phoning home
    ... > It seems that the majority of bots connect to an IRC server in order to ... > the avenue for abuse of an infected machine is via connection to IRC ... > into in order to gain access to IRC servers outside our network? ... even without bots in the picture. ...
    (Firewall-Wizards)