Er yes, it is pretty clear I have been hacked <g>. My query was mainly to see whether the pattern of this particular was familiar to anyone (as it couldn't match its "signature" to any known Linux attacks I could find on the net).
Forgot to mention (in case it is of any interest) that in creating the dnsquery script it apparently picks a user name at random to own it (on the two infected systems it was two completely different users -- one a known/standard kind of user (majordom) and one not).
Hi folks,
I recently experienced an attack on two older (6.x) Redhat servers and have not been able to find anything on the net that sounds like it (one box did not use OpenSSL so it could not have come in that way) so I thought I would inquire.
Once the attack gets root (not clear how --...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.