OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: hacked by bind eploit--can someone help me???
From: C.M. Wong (wongcmEP.COM.MY)
Date: Wed Jun 28 2000 - 09:48:21 CDT


I suggest you format the machine now. This exploit is quite widely spread.
Rebuilt your machine with the latest linux RH kernel (2.2.16-3) and download
the latest bind package (8.2.2-p5) from www.isc.org. Compile it and run it
in a chroot env with a normal user.

If you got an extra server to spare, keep the hacked one and try to track
the little bugger down... provided you still got your logs. :)

Rgrds,
Wong.

> -----Original Message-----
> From: Focus on Linux Mailing List
> [mailto:FOCUS-LINUXSECURITYFOCUS.COM]On Behalf Of swamy
> Sent: Wednesday, June 28, 2000 9:20 PM
> To: FOCUS-LINUXSECURITYFOCUS.COM
> Subject: hacked by bind eploit--can someone help me???
>
>
> hello,,
>
> My server is hacked :
>
> there is a directory :/var/named/ADMROCKS created by the hacker,,
> a psuedo login shell : prick
>
> i am able to replace the origianal login shell ,, but my
> nameserver is still
> not working properly... 'am using redhat 6.1 version
>
>
> can some one please help me???
>
> reply,
>
>
> swamy..