Re: Argh, infected!

Dan Osterrath <[email protected]>
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
Am Montag, 13. Oktober 2003 14:22 schrieb Sam Barnett-Cormack:
> If chkrootkit relied on binaries being unstripped it would be kinda
> useless.

OK, it would be very easy to "hide" the trojan horse this way.
I've seen several postings in the google groups that mentions false alarms on 
netstat.
But I'd like to see other people having this problem with a recent version 
(LFS 5.0pre) just to be sure. Probably www.tazenda.demon.co.uk has been 
comprimised for the time when LFS 4.x was recent and everyone got a trojaned 
version.
You might try to reinstall net-tools and see what happens.

-- 
----------------------------------------------------------------------
%> ln -s /dev/null /dev/brain
%> ln -s /dev/urandom /dev/world
%> dd if=/dev/world of=/dev/brain

-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)

iD8DBQA/ipt59NbB8EM160MRAjt2AJ9dsy1X2PB5tV4Ytt8X40FAjphGuwCg6pls
YHEjf3AUVi8NFrBfclr1G/E=
=A62Y
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.