Re: sequences in the auth.log

看板FB_security作者時間21年前 (2004/08/13 22:56), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串5/12 (看更多)
Heya, this is probably the same piece of malware that has been discussed on f-d recently. The username/password combination guest and test are hardcoded into a little statically linked binary which is commonly used together with a SYN scanner. Chances are good these attempts are coming from a compromised box - you may want to look into that if it is in your realms. If you need more info, I disassembled them both and made a quick analysis, check the f-d archives. Cheers, J. _______________________________________________ freebsd-security@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
文章代碼(AID): #117DQ200 (FB_security)
討論串 (同標題文章)
文章代碼(AID): #117DQ200 (FB_security)