Security Incidents mailing list archives
Re: ingreslock message
From: xm () GEEKMAFIA DYNIP COM (Ex Machina [xm])
Date: Mon, 13 Mar 2000 10:02:53 -0500
I've seen this recently as the default command in in the adm-bind_exp.c (ADM named 8.2/8.2.1 NXT remote overflow). It simply started another inetd using a config in /tmp/bob which was immediately deleted afterwards. Ex Machina (xm () geekmafia dynip com) http://geekmafia.dynip.com/~xm/ phone: 1-877-LPT-WHIP icq: 3387005 aim: ExMachina public.key: finger.me Hire me: 18 yrs old RI Linux BSD UNIX C++ Perl HTML TCP/IP Security On Fri, 10 Mar 2000, Jens Hektor wrote:
Date: Fri, 10 Mar 2000 05:53:17 -0000 From: Jens Hektor <hektor () RZ RWTH-AACHEN DE> To: INCIDENTS () SECURITYFOCUS COM Subject: Re: ingreslock message Hi,I logged this: Mar 5 15:58:23 monitor tcplogd: ingreslock connection attempt from sleipnir1.cs.ucl.ac.uk what does the ingreslock mean and what was this person trying to do?reading this in the morning and starring later on the logs of a cracked box I see the same adress in the wtmp logs. The machine had beside other trojans an inetd with compiled-in backdoor at ingreslock. Will inform the people at ucl.ac.uk about that. Bye, Jens
Current thread:
- ingreslock message, (continued)
- ingreslock message Dino Amato (Mar 05)
- Re: ingreslock message Graeme Fowler (Mar 07)
- Re: ingreslock message Dino Amato (Mar 07)
- Re: ingreslock message Robert Graham (Mar 07)
- firewall abusing Przemyslaw Frasunek (Mar 07)
- Re: ingreslock message H D Moore (Mar 07)
- Re: ingreslock message Eric Maiwald (Mar 07)
- Re: auto-reporting to ISPs John Nemeth (Mar 07)
- UDP flood 28001-28003 George (Mar 07)
- Re: ingreslock message Jens Hektor (Mar 09)
- Re: ingreslock message Ex Machina [xm] (Mar 13)
- Re: ingreslock message Jens Hektor (Mar 13)