Security Incidents mailing list archives
Re: AMDROCKS
From: lance () SPITZNER NET (Lance Spitzner)
Date: Fri, 26 May 2000 16:38:15 -0500
On Fri, 26 May 2000, Alejandro wrote:
Recently I discovered a folder called ADMROCKS located on my server inside /var/named, and I can't figure it out, how it was made, if I was hacked, or if my machine is compromissed... Other strange thing was that I discovered a line on /etc/inetd.conf invoking an interactive shell owned by root. Im using linux redhat 6.1.
See "Know Your Enemy: A Forensic Analysis". This writeup has more then everything you ever wanted to know about the attack:) http://www.enteract.com/~lspitz/forensics.html lance
Current thread:
- Re: invalid icmp in linux?, (continued)
- Re: invalid icmp in linux? Jose Nazario (May 28)
- weird scan pattern Joe H (May 28)
- Re: weird scan pattern Russell Fulton (May 29)
- IDS: Scan of the week Lance Spitzner (May 30)
- 5 scans of 12345 in a couple of hours. AUSCERT#36349 Russell Fulton (May 31)
- Taiwan server compromise Claudiu Costin (May 26)
- Re: Taiwan server compromise Vortex (May 26)
- port 44767 activity Nathan Fain (May 28)
- Re: AMDROCKS Alejandro (May 26)
- Re: AMDROCKS J. S. Townsley (May 26)
- Re: AMDROCKS Lance Spitzner (May 26)
- Re: AMDROCKS Matthew F. Caldwell (May 26)
- CERT's Handbook for Computer Security Incident Response Teams (CSIRTs) Elias Levy (May 26)
