|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Subject: Re: ingreslock message
From: Jens Hektor (hektor
RZ.RWTH-AACHEN.DE)Date: Thu Mar 09 2000 - 23:53:17 CST
- Next message: Stephen Cooper: "Re: Undernet/telnet attempts?"
- Previous message: Parkin, Miles: "Re: Port 33434 and decoy-scanning"
- In reply to: Dino Amato: "ingreslock message"
- Next in thread: Ex Machina [xm]: "Re: ingreslock message"
- Next in thread: Jens Hektor: "Re: ingreslock message"
- Reply: Jens Hektor: "Re: ingreslock message"
- Reply: Ex Machina [xm]: "Re: ingreslock message"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Hi,
> I logged this:
> Mar 5 15:58:23 monitor tcplogd: ingreslock connection
> attempt from sleipnir1.cs.ucl.ac.uk what does the
> ingreslock mean and what was this person trying to do?
reading this in the morning and starring later on the
logs of a cracked box I see the same adress in the wtmp
logs.
The machine had beside other trojans an inetd with
compiled-in backdoor at ingreslock.
Will inform the people at ucl.ac.uk about that.
Bye, Jens
- Next message: Stephen Cooper: "Re: Undernet/telnet attempts?"
- Previous message: Parkin, Miles: "Re: Port 33434 and decoy-scanning"
- In reply to: Dino Amato: "ingreslock message"
- Next in thread: Ex Machina [xm]: "Re: ingreslock message"
- Next in thread: Jens Hektor: "Re: ingreslock message"
- Reply: Jens Hektor: "Re: ingreslock message"
- Reply: Ex Machina [xm]: "Re: ingreslock message"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]