Security Incidents mailing list archives

Kaiten.exe DoS ?


From: C Boening <txfmfdoc () HOME COM>
Date: Sun, 6 May 2001 10:45:55 -0400

Has anyone ever heard of a DoS named Kaiten? I  have been able to find
only one relevant reference on the net for kaiten.c ,  which lists the
code for it. I  have found on one of my servers a program nammed
Kaiten.exe (installed on 15 April 01, two minutes AFTER someone hacked
into one of our other servers using the IIS unicode exploit.The intruder
put kaiten.exe at the end of his script used to hack in) for which I
have found absolutely no info anywhere. OS is WinNT server 4.0 . File
size for Kaiten.exe is 52 k's, whereas the kaiten.c is only 32 k's. I am
new to the whole security business, moving up from tech support... I
have copied Kaiten.exe on an NT box removed from the network and sure
enough it tried to connect to the internet ...


Current thread: