Security Incidents mailing list archives

Re: any1 stumbled across eCkit ?


From: Ian Jones <ian () dsl081-056-052 sfo1 dsl speakeasy net>
Date: Mon, 26 Nov 2001 15:35:36 -0800

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Patrick van Zweden <patrick () vanzweden nl eu org> writes:

In /lib/ldd.so/ i found the patch script and a file called td. Strings
revealed that it is some kind of testing program but i don't know for sure. 

This is most likely the tfn[2k] daemon. It is used to serve the master
in a DDoS network. You can read more here:

http://www.cert.org/incident_notes/IN-99-07.html#tfn
http://packetstorm.decepticons.org/distributed/TFN2k_Analysis.htm

-----BEGIN PGP SIGNATURE-----
Comment: Keeping the world safe for geeks.

iD8DBQE8AtHIwBVKl/Nci0oRAuNHAJ0UexI3uf6nMBIf8ROfwM2kDUSH3ACfWKZt
kCRXx8yIa++OuRYhDt2lf6s=
=Bvru
-----END PGP SIGNATURE-----

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see: http://aris.securityfocus.com


Current thread: