Re: compromised box. please advice

2003-06-24 Thread Shri Shrikumar
On Tue, 2003-06-24 at 21:36, Elizabeth Barham wrote: > Shri writes: > > > The program was called bd.c and was created on June the 6, so all > > the logs I have are too new to be able to do any real kind of > > tracking down. > > Does the code in: > > http://kaizo.org/mirrors/phrack/phrack58/p58-

Re: compromised box. please advice

2003-06-24 Thread Elizabeth Barham
Shri writes: > The program was called bd.c and was created on June the 6, so all > the logs I have are too new to be able to do any real kind of > tracking down. Does the code in: http://kaizo.org/mirrors/phrack/phrack58/p58-0x07 look familiar? One of the source files is named bd.c ("backdoor")

compromised box. please advice

2003-06-24 Thread Shri Shrikumar
Hi all, I was just trying to find out why I was having trouble with nfs when I spotted a program being run from /tmp and on investigation, it seemed like someone had managed to get apache to download a c program, compile and run it. This program opened port 5000 and the https port (maybe a couple