[CentOS] attack

Thu Dec 24 12:45:38 UTC 2009
Manu Verhaegen <maverh at telenet.be>

Hi,

i have Check my tmp directory and subdirectorys for std, udp.pl no file exist.  Also i have check /etc/passwd and /etc/shadow for unusual users.  

regards

-----Oorspronkelijk bericht-----
Van: centos-bounces at centos.org [mailto:centos-bounces at centos.org] Namens Thomas Dukes
Verzonden: donderdag 24 december 2009 13:08
Aan: 'CentOS mailing list'
Onderwerp: Re: [CentOS] attack

 

> -----Original Message-----
> From: centos-bounces at centos.org 
> [mailto:centos-bounces at centos.org] On Behalf Of Manu Verhaegen
> Sent: Thursday, December 24, 2009 7:04 AM
> To: CentOS mailing list
> Subject: Re: [CentOS] attack
> 
> at the moment everiting is solved i have block the IP adress 
> but i d'ont have found the script
> 

So you are the attacker.  Happened to me a couple weeks ago.

Check your tmp directory and subdirectory for std, udp.pl.  Also check
/etc/passwd and /etc/shadow for unusual users.  Should be at the very bottom
of those files.

_______________________________________________
CentOS mailing list
CentOS at centos.org
http://lists.centos.org/mailman/listinfo/centos