OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: ingreslock message
From: Jens Hektor (hektorRZ.RWTH-AACHEN.DE)
Date: Mon Mar 13 2000 - 11:36:39 CST


Hi,

"Ex Machina [xm]" wrote:
>
> I've seen this recently as the default command in in the adm-bind_exp.c
> (ADM named 8.2/8.2.1 NXT
> remote overflow). It simply started another inetd using a config in
> /tmp/bob which was immediately deleted afterwards.

this is was we see *very* often, becuse itīs simpler, a compiled-in
backdoor is less frequent.

Bye, Jens

-- 
Jens Hektor, RWTH Aachen, Rechenzentrum, Seffenter Weg 23, 52074 Aachen 
Computing Center Technical University Aachen, firewalls/network security
mailto:hektorRZ.RWTH-Aachen.DE, Tel.: +49 241 80 4866 
Private: Rochusstr. 26, D52062 Aachen, Fon: +49 241 29888, Fax: % 29889