Steve Holdoway
2011-11-15 22:47:49 UTC
I'm trying to find out any info about malware that generates an
executable called barbut[0-9], owned by root that keeps infecting a
CentOS5 - patched to current - server.
My google fu gets me to posts from 2007, and I'd be surprised if the
same attack vector would be open. Still looking, but v. worried about
the root ownership...
rkhunter, log mining, etc find nothing untoward.
Please feel free to contact me offlist if you feel it more appropriate.
Cheers,
Steve
executable called barbut[0-9], owned by root that keeps infecting a
CentOS5 - patched to current - server.
My google fu gets me to posts from 2007, and I'd be surprised if the
same attack vector would be open. Still looking, but v. worried about
the root ownership...
rkhunter, log mining, etc find nothing untoward.
Please feel free to contact me offlist if you feel it more appropriate.
Cheers,
Steve
--
Steve Holdoway BSc(Hons) MNZCS <***@greengecko.co.nz>
http://www.greengecko.co.nz
MSN: ***@greengecko.co.nz
Skype: sholdowa
Steve Holdoway BSc(Hons) MNZCS <***@greengecko.co.nz>
http://www.greengecko.co.nz
MSN: ***@greengecko.co.nz
Skype: sholdowa