Re: recommendation on an exploit and malicious software

From: Mark Newby (mark.newby@ntlworld.com)
Date: 05/25/02


From: Mark Newby <mark.newby@ntlworld.com>
Date: Sat, 25 May 2002 13:44:50 +0100

Andrew wrote:
> Hi,
>
> I am working on an assignment on analysis of an exploit and malicious
> software on platform NT or Linux --- not any famous one, must be something
> new, any recommendations?
>
>
> Thank you,
>
>

I think the `Tuxkit' rootkit from Tuxtendo is quite new too. a client
of mine recently had their Red Hat 7.2 Web server cracked into and this
rootkit installed.

search the archives of <incidents@securityfocus.com> for subject:

        "Tuxkit (Optic Kit?) -cracked (/dev/tux)"

(it turns out the kit was a modified Tuxkit, where /dev/tux/ssh2/logo
had been modified to say `Optic Kit' instead of `Tuxkit').

mark



Relevant Pages