|
|||||||||||
|
hpd, afb, sc, and sn
From: Gordon Chamberlin <glac(at)visualize.com>
Date: Fri Dec 20 2002 - 16:11:31 EST
The files:
The following line is in /etc/rc.local:
The contents of hpd are:
namp reports the following ports open:
According to an rpm -V, all kinds of binaries have been changed: ps, top, netstat, ifconfig, ... I copied a good version of ps in and found the two afb processes running. Anyone know about this hack, what afb does and/or how they usually get in?
Embarrassedly,
-- Gordon Chamberlin Software Architect Visualize, Inc. http://www.visualize.com ---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.comReceived on Fri Dec 20 17:13:40 2002 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:55 EDT |
||||||||||
|
|||||||||||