Snort mailing list archives

Re: ATTACK-RESPONSES id check returned root


From: Chris Romano <romano.chris () gmail com>
Date: Fri, 21 Oct 2005 13:48:11 -0400

On 10/21/05, Patrick Walsh <pwalsh () esoft com> wrote:

SUCKIT v 1.1c - New, singing, dancing, world-smashing rewtkit *.*
(c)oded by sd () sf cz &amp; devik () cdi cz, 2001
Configuring ./sk:.OK!.[attacker () badass cz ~/sk10]$ telnet lamehost.com<http://lamehost.com>
80.Trying 192.160.0.2.... Connected to lamehost.com..Escape character

Looks like someone viewed this phrack article:

http://www.phrack.org/phrack/58/p58-0x07

which triggered the rule.



That seems to be it. I feel much better now.

thanks everyone.

Chris

Current thread: