|
|||||||||||
|
Re: ping22: can not kill this process
From: Jan Luehr <jan(at)stephan.homeunix.net>
Date: Mon Dec 31 2007 - 08:03:53 EST
Am Montag, 31. Dezember 2007 schrieb Mike Wang:
This implies some things (likely):
If so, root privilges would have been acquired and ping222x would be hidden, executed as root, etc. (There is a slight chance that the binary drops its privileges down to www-data as an act of deception, but there are better ways for deception/hiding if root-privileges are gained)
2. The respawing binary has to be kept somewhere. A few explainations are
possible:
In order to exclude a) you can shut down your apache for a moment and look if ping22 is able to respawn.
Keep smiling
-- To UNSUBSCRIBE, email to debian-security-REQUEST@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.orgReceived on Mon Dec 31 08:51:37 2007 This archive was generated by hypermail 2.1.8 : Wed Mar 19 2008 - 06:54:49 EDT |
||||||||||
|
|||||||||||