Security Basics mailing list archives

ASPXSPY


From: "Jared C. Henry" <jared.henry () heartlandsig com>
Date: Wed, 1 Oct 2008 16:33:09 -0500


Hey Everyone,
I had a quick question. I was looking at one of my servers awhile ago
and discovered an aspx file called "kk.aspx". After looking at the code
it was quickly determined that it was a rootkit. After launching the
page from the web and discovering it's capabilities I started to get
sick at my stomach. Has anyone had any type of experience with this? I
deleted the files. The server is running server 2000. Is there any type
of recent exploits that would allow this that you know of?

Thanks,
Jared



Current thread: