Security Basics mailing list archives

optic rootkit / xsf/xchk?


From: Jan De Luyck <ml () kcore org>
Date: Wed, 29 Oct 2003 16:55:24 +0100

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hello,

Recently one of the rather old linux-boxes at my company got into trouble 
(didn't know it existed earlier). Did some checking, and the box has been 
rooted.

I've been looking for more information on this rootkit, but I have been unable 
to find anything besides this:

http://cert.uni-stuttgart.de/archive/incidents/2002/01/msg00148.html

So I'm wondering if anyone can tell me some more about this thing?

Reinstallation is planned to happen soon.

Thanks.

Jan
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)

iD8DBQE/n+LwUQQOfidJUwQRAqU4AJ9J8NTqanZIKTElMN8RNCwbCPJbqwCfUZ2Z
bQhc9qlNZ120xx0y8WdtWLA=
=TQIq
-----END PGP SIGNATURE-----


---------------------------------------------------------------------------
Forum Systems PRESIDIO: PGP / XML GATEWAY APPLIANCE
The Presidio integrates PGP data encryption and XML Web Services security to
simplify the management and deployment of PGP and reduce overall PGP costs
by up to 80%.
FREE WHITEPAPER & 30 Day Trial -
http://www.securityfocus.com/sponsor/ForumSystems_security-basics_031027
----------------------------------------------------------------------------


Current thread: