Security Incidents mailing list archives

Re: DoS Tool Identification


From: Martin <broadcast () mail ptraced net>
Date: Wed, 25 Feb 2004 19:10:51 -0300


strings bd.out reveals:



Can't execve shell!
/bin/sh
$HOMEDIRHOMEDIR
Can't fork subshell, there is no way...
Can't open a tty, all in use ?
/dev/null
Done, pid=%d
F**K: Can't fork child (%d)
F**K: Can't bind udp  socket (%d)
F**K: Can't allocate udp  socket (%d)
/usr/local/apache/bin/httpd
FUCK: Can't allocate raw socket (%d)
using old...
/usr/sbin/named
BD_Init: Starting backdoor daemon...

Seems like a backdoor daemon running on an UDP port.


---------------------------------------------------------------------------
----------------------------------------------------------------------------


Current thread: