Security Incidents mailing list archives

Re: .:: 14x :: Information :: New DDoS/Trojan ::.


From: rgg () SOLARIUM CS BUAP MX (Lic. Rodolfo Gonzalez Gonzalez)
Date: Thu, 15 Jun 2000 11:47:39 -0500


Hello,

Since several days ago I'm getting these  messages in a RedHat 6.1 box:

Jun 11 04:04:23 mail inetd[14085]: auth/tcp: bind: Address already in use
Jun 11 04:14:23 mail inetd[14085]: auth/tcp: bind: Address already in use

Since in.inetd is running (and nothing else sholud be binding that port),
I'm afraid that something is wrong here. Is this a kind of signature of
the trojan?.

Regards,
Rodolfo.

P.S. I also get the message when I restart inetd.


Current thread: