Re: TCP 6006 and echo (port 7) Mandrake (possible new trojan?)

From: Wojtek Walczak (gminick@hacker.pl)
Date: 12/09/02


From: Wojtek Walczak <gminick@hacker.pl>
Date: Mon, 9 Dec 2002 16:56:25 +0000 (UTC)

Dnia Sun, 08 Dec 2002 13:58:49 -0800, Joshua Kuo napisał(a):
># telnet localhost 6006
> Trying 127.0.0.1...
> Connected to localhost.
> Escape character is '^]'.
> SSH-1.5-OpenSSH-2.9.2

type

netstat -tupan

get a PID of that process, then do

ls -l /proc/PID/exe

and you'll find location of that server's binary.
Are you that person, who placed sshd binary in place you'll find out?

-- 
[ ] gminick (at) underground.org.pl  http://gminick.linuxsecurity.pl/ [ ]
[ "Po prostu lubie poranna samotnosc, bo wtedy kawa smakuje najlepiej." ]


Relevant Pages

  • Re: Postfix refusing connections from local SMTP
    ... > Try telnet localhost 25 and see if it answers. ... Escape character is '^]'. ... Connection closed by foreign host. ... the problem persists. ...
    (comp.os.linux.security)
  • Re: How to determine the version of sshd
    ... Escape character is '^]'. ... This will work only iff have #VersionAddendum commented out in ... >the version of sshd running on a FreeBSD system? ...
    (freebsd-questions)
  • Cyrus IMAP LOGINDISABLED
    ... No longer allow me to login with plaintext, only SSL. ... From telnet localhost 143: ... Escape character is '^]'. ...
    (Fedora)
  • Problems with localhost
    ... I have a session in a machine with solaris 8 ... Escape character is '^]'. ... When I use #telnet localhost port, where port isn't 80 it's OK again. ...
    (comp.unix.solaris)
  • Re: Enabling telnet
    ... telnet localhost 9734 ... My amavisd-new mail settings ... Escape character is '^]'. ...
    (Fedora)