OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: Rooted through in.identd on Red Hat 6.0
From: Dmitry Alyabyev (dimitryAL.ORG.UA)
Date: Thu Apr 20 2000 - 03:24:57 CDT


Wednesday, April 19, 2000, 8:02:13 AM, Del wrote:

> Hi,

> A client was hacked last week by what looked like a buffer
> overflow through in.identd. This was on a Red Hat 6.0
> box.

[skip]

echo "2 sh" >>> /dev/cui220 ; echo "2 slice2" >> /dev/cui220
> ;
echo "2 bnc" >>> /dev/220 ; echo "4 6667" >> /dev/cui221 ;
echo "3 15678" >>> /dev/cui221 ; echo "2 pt07" >> /dev/cui220
> ;
echo "3 1679" >>> /dev/cui221; echo "3 5454" >> /dev/cui221;

Could you explain a reason of these lines above ?
What is /dev/cui220 (/dev/cui221) ?

TIA

--
Best rgds,                           Dimitry