OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Aaron Young (acyoungnysernet.org)
Date: Mon Dec 31 2001 - 09:31:05 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    ('binary' encoding is not supported, stored as-is)
    Anyone seen this before? In the last month one of the
    sites I manage had an intrusion that forced us to take
    our server offline. After putting Zone Alarm on the
    Win2K server to see if it caught anything roque trying
    to access the Internet, I found the following alert:

    Do you want to allow
    \??\C:\WINNT\system32\winlogin.exe to access the
    Internet?

    Since the path to winlogin.exe began with an unknown
    character (\??\) I found this to be suspicious.

    A.