Displaying 5 results from an estimated 5 matches for "suckit".
2003 Dec 02
0
Re: [leaf-user] SucKIT root-kit
[This email is either empty or too large to be displayed at this time]
2009 Jan 26
1
I may have been rooted - but I may not!?
...hose
needed for RTP, IAX2 and SIP - there is no other public access and no user
accounts.
Having fixed the vlan issue, Asterisk is running fine.
I re-created /dev/kmem, but it's missing at subsequent reboots.
I have Googled many references to the IDT table problem being associated
with the SuckIT rootkit, but I can find no evidence that it's installed.
OK, bearing in mind that I will go ahead and reinstall the server (no biggie
as I have Trixbox config backups and installing TB is not a big task), I
just wanted to check whether there were any IDT table issues that may *NOT*
be rootkit...
2003 Dec 07
5
possible compromise or just misreading logs
I am not sure if I had a compromise but I am not sure I wanted some other
input.
I noticed in this in my daily security run output:
pc1 setuid diffs:
19c19
< 365635 -rwsr-xr-x 1 root wheel 204232 Sep 27 21:23:19 2003
/usr/X11R6/bin/xscreensaver
---
> 365781 -rwsr-xr-x 1 root wheel 205320 Dec 4 07:55:59 2003
/usr/X11R6/bin/xscreensaver
It was the only file listed and I didn't
2006 Feb 18
0
Does your rkhunter do an md5 check?
...;Scalper Worm'... [ OK ]
Rootkit 'Shutdown'... [ OK ]
Rootkit 'SHV4'... [ OK ]
Rootkit 'SHV5'... [ OK ]
Rootkit 'Sin Rootkit'... [ OK ]
Rootkit 'Slapper'... [ OK ]
Rootkit 'Sneakin Rootkit'... [ OK ]
Rootkit 'Suckit Rootkit'... [ OK ]
Rootkit 'SunOS Rootkit'... [ OK ]
Rootkit 'Superkit'... [ OK ]
Rootkit 'TBD (Telnet BackDoor)'... [ OK ]
Rootkit 'TeLeKiT'... [ OK ]
Rootkit 'T0rn Rootkit'... [ OK ]
Rootkit 'Trojanit Kit'... [ OK...
2004 Sep 18
8
Attacks on ssh port
Hi,
Is there a security problem with ssh that I've missed???
Ik keep getting these hords of:
Failed password for root from 69.242.5.195 port 39239 ssh2
with all kinds of different source addresses.
They have a shot or 15 and then they are of again, but a little later on
they're back and keep clogging my logs.
Is there a "easy" way of getting these ip-numbers added to