search for: suckit

Displaying 5 results from an estimated 5 matches for "suckit".

2003 Dec 02
0
Re: [leaf-user] SucKIT root-kit
[This email is either empty or too large to be displayed at this time]
2009 Jan 26
1
I may have been rooted - but I may not!?
...hose needed for RTP, IAX2 and SIP - there is no other public access and no user accounts. Having fixed the vlan issue, Asterisk is running fine. I re-created /dev/kmem, but it's missing at subsequent reboots. I have Googled many references to the IDT table problem being associated with the SuckIT rootkit, but I can find no evidence that it's installed. OK, bearing in mind that I will go ahead and reinstall the server (no biggie as I have Trixbox config backups and installing TB is not a big task), I just wanted to check whether there were any IDT table issues that may *NOT* be rootkit...
2003 Dec 07
5
possible compromise or just misreading logs
I am not sure if I had a compromise but I am not sure I wanted some other input. I noticed in this in my daily security run output: pc1 setuid diffs: 19c19 < 365635 -rwsr-xr-x 1 root wheel 204232 Sep 27 21:23:19 2003 /usr/X11R6/bin/xscreensaver --- > 365781 -rwsr-xr-x 1 root wheel 205320 Dec 4 07:55:59 2003 /usr/X11R6/bin/xscreensaver It was the only file listed and I didn't
2006 Feb 18
0
Does your rkhunter do an md5 check?
...;Scalper Worm'... [ OK ] Rootkit 'Shutdown'... [ OK ] Rootkit 'SHV4'... [ OK ] Rootkit 'SHV5'... [ OK ] Rootkit 'Sin Rootkit'... [ OK ] Rootkit 'Slapper'... [ OK ] Rootkit 'Sneakin Rootkit'... [ OK ] Rootkit 'Suckit Rootkit'... [ OK ] Rootkit 'SunOS Rootkit'... [ OK ] Rootkit 'Superkit'... [ OK ] Rootkit 'TBD (Telnet BackDoor)'... [ OK ] Rootkit 'TeLeKiT'... [ OK ] Rootkit 'T0rn Rootkit'... [ OK ] Rootkit 'Trojanit Kit'... [ OK...
2004 Sep 18
8
Attacks on ssh port
Hi, Is there a security problem with ssh that I've missed??? Ik keep getting these hords of: Failed password for root from 69.242.5.195 port 39239 ssh2 with all kinds of different source addresses. They have a shot or 15 and then they are of again, but a little later on they're back and keep clogging my logs. Is there a "easy" way of getting these ip-numbers added to