Vulnerability Development mailing list archives

Crazy modprobe


From: Rodolfo Ponteado <netpatrol () ieg com br>
Date: Sat, 06 Oct 2001 03:30:38 -0300

Please could you tell me what is this

First i scaned my own box

Interesting ports on blacksoul.raphouse.org (***.***.***.***):
(The 1542 ports scanned but not shown below are in state: closed)
Port State Service
22/tcp open ssh
25/tcp open smtp
80/tcp open http
110/tcp open pop-3
113/tcp open auth

Remote operating system guess: Linux Kernel 2.4.0 - 2.4.5 (X86)

And then i looked at the syslog entry

Oct 6 03:16:41 blacksoul modprobe: modprobe: Can't locate module \234???@
Oct 6 03:16:41 blacksoul modprobe: modprobe: Can't locate module \234???@
Oct 6 03:16:41 blacksoul modprobe: modprobe: Can't locate module ????@
Oct 6 03:16:41 blacksoul modprobe: modprobe: Can't locate module ????@
Oct 6 03:16:41 blacksoul last message repeated 3 times
Oct 6 03:18:04 blacksoul modprobe: modprobe: Can't locate module \234???@
Oct 6 03:18:04 blacksoul modprobe: modprobe: Can't locate module \234???@
Oct 6 03:18:04 blacksoul modprobe: modprobe: Can't locate module ????@
Oct 6 03:18:04 blacksoul modprobe: modprobe: Can't locate module ????@
Oct 6 03:18:05 blacksoul last message repeated 2 times
Oct 6 03:18:19 blacksoul modprobe: modprobe: Can't locate module ????@
Oct 6 03:18:19 blacksoul modprobe: modprobe: Can't locate module ????@
Oct 6 03:18:19 blacksoul modprobe: modprobe: Can't locate module ????@
Oct 6 03:18:19 blacksoul modprobe: modprobe: Can't locate module ????@

The mail server is qmail running in inetd
the auth server is nullident running in xinetd if libsafe prelodied

Thank you



Current thread: