Security Incidents mailing list archives

Re: ingreslock message


From: hektor () RZ RWTH-AACHEN DE (Jens Hektor)
Date: Fri, 10 Mar 2000 05:53:17 -0000


Hi,

I logged this:
Mar  5 15:58:23 monitor tcplogd: ingreslock connection
attempt from sleipnir1.cs.ucl.ac.uk what does the
ingreslock mean and what was this person trying to do?

reading this in the morning and starring later on the
logs of a cracked box I see the same adress in the wtmp
logs.

The machine had beside other trojans an inetd with
compiled-in backdoor at ingreslock.

Will inform the people at ucl.ac.uk about that.

Bye, Jens


Current thread: