Security Incidents mailing list archives
Re: any1 stumbled across eCkit ?
From: Ian Jones <ian () dsl081-056-052 sfo1 dsl speakeasy net>
Date: Mon, 26 Nov 2001 15:35:36 -0800
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Patrick van Zweden <patrick () vanzweden nl eu org> writes:
In /lib/ldd.so/ i found the patch script and a file called td. Strings revealed that it is some kind of testing program but i don't know for sure.
This is most likely the tfn[2k] daemon. It is used to serve the master in a DDoS network. You can read more here: http://www.cert.org/incident_notes/IN-99-07.html#tfn http://packetstorm.decepticons.org/distributed/TFN2k_Analysis.htm -----BEGIN PGP SIGNATURE----- Comment: Keeping the world safe for geeks. iD8DBQE8AtHIwBVKl/Nci0oRAuNHAJ0UexI3uf6nMBIf8ROfwM2kDUSH3ACfWKZt kCRXx8yIa++OuRYhDt2lf6s= =Bvru -----END PGP SIGNATURE----- ---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
Current thread:
- Re: any1 stumbled across eCkit ? Patrick van Zweden (Nov 26)
- Re: any1 stumbled across eCkit ? Ian Jones (Nov 26)
- <Possible follow-ups>
- any1 stumbled across eCkit ? Patrick van Zweden (Nov 26)
- Re: any1 stumbled across eCkit ? Fredrik Ostergren (Nov 29)
- RE: any1 stumbled across eCkit ? Ryan Sweat (Nov 29)