Re: Argh, infected!
Dan Osterrath <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
Am Montag, 13. Oktober 2003 14:22 schrieb Sam Barnett-Cormack: > If chkrootkit relied on binaries being unstripped it would be kinda > useless. OK, it would be very easy to "hide" the trojan horse this way. I've seen several postings in the google groups that mentions false alarms on netstat. But I'd like to see other people having this problem with a recent version (LFS 5.0pre) just to be sure. Probably www.tazenda.demon.co.uk has been comprimised for the time when LFS 4.x was recent and everyone got a trojaned version. You might try to reinstall net-tools and see what happens. -- ---------------------------------------------------------------------- %> ln -s /dev/null /dev/brain %> ln -s /dev/urandom /dev/world %> dd if=/dev/world of=/dev/brain -- http://linuxfromscratch.org/mailman/listinfo/lfs-security FAQ: http://www.linuxfromscratch.org/faq/ Unsubscribe: See the above information page
signature.asc
(application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.1 (GNU/Linux) iD8DBQA/ipt59NbB8EM160MRAjt2AJ9dsy1X2PB5tV4Ytt8X40FAjphGuwCg6pls YHEjf3AUVi8NFrBfclr1G/E= =A62Y -----END PGP SIGNATURE-----