Security Incidents mailing list archives

Re: LJK2 rootkit?


From: jose () BIOCSERVER BIOC CWRU EDU (Jose Nazario)
Date: Tue, 16 May 2000 17:40:18 -0400


On Tue, 16 May 2000, Felix Schueren wrote:

sshconfig:
total 574
drwxr-xr-x   2 root     root         1024 May 16 07:53 ./
drwxr-xr-x   9 root     root         1024 May 16 07:53 ../
-rwxr-xr-x   1 root     root       580696 Feb 18 21:24 RK1ssh*

looks like a trivial variant of LRK4, yet again. *shrug* not a bad design
for a rootkit, but heck, not perfect (obviously). looks like you know what
you're doing for cleanup, but for some real fun, check the
/root/.ssh/known-hosts file. often, 3133+ hax0r d00dz will forget to not
log known hostkeys and it thus retains a list of hosts they connected to.

jose nazario                                    jose () biochemistry cwru edu
PGP fingerprint: 89 B0 81 DA 5B FD 7E 00  99 C3 B2 CD 48 A0 07 80
Public key available at http://biocserver.cwru.edu/~jose/pgp-key.asc


Current thread: