The UNIX and Linux Forums  


Go Back   The UNIX and Linux Forums > Top Forums > UNIX for Advanced & Expert Users
.
google unix.com




View Single Post in the UNIX and Linux Forums - Click on the Thread or Permalink to View Entire Thread -->
  #9 (permalink)  
Old 12-17-2007
tlippy01 tlippy01 is offline
Registered User
  
 

Join Date: Dec 2007
Posts: 1
our compromised system

We're having this problem as well, also on RHEL4. Does anyone have an idea of how their machines were compromised initially? We don't want to open up the same vulnerability again. I've attached the three /bin/mount* files we found on the compromised machine. There were other similarly compromised binaries as well, such as touch, basename and cat.
-Tom

Moderator's note: I have just approved the attachment so it should now be available for downloading. Download it with caution! It is suspected of being malware. --- Perderabo
Attached Files
File Type: gz evil_mount.tar.gz (515.7 KB, 7 views)

Last edited by Perderabo; 12-17-2007 at 08:25 PM.. Reason: Approve attachment