[Centos] Think someone has got into my server...

WipeOut

wipe_out at users.sourceforge.net
Tue Jan 11 10:19:23 UTC 2005


I have just run chkrootkit on my server and have the following two 
suspicious entries..

Searching for suspicious files and dirs, it may take a while...
/usr/lib/perl5/5.8.0/i386-linux-thread-multi/.packlist

and further down..

Checking `bindshell'... INFECTED (PORTS:  465)

Anyone have any advice for getting rid of it??

Later..





More information about the CentOS mailing list