gtn bot ?
Paul Schmehl
pauls at utdallas.edu
Thu Oct 18 08:19:15 PDT 2007
--On Thursday, October 18, 2007 08:28:46 -0400 Grant Peel
<gpeel at thenetnow.com> wrote:
> Hi all,
>
> I missed one to. I have never seen this process befor, any ideas?
>
> 6313 1 Mon Oct 15 19:34:39 2007 0:02.71 [prox]
The problem with this approach is that the bad guys don't try to accomodate
you by using common naming conventions. Searching for gtn or prox or
eggdrop will most likely be a fruitless exercise.
What you need to do is 1) identify what it is by locating it and all its
associated files on the hard drive, 2) determing how to stop it so you can
clean up and 3) figuring out how the box was broken into so you can prevent
a reoccurrence.
If you need help with that, I would suggest taking it private. It's best
not to post these kinds of details in an open forum. I'd be happy to help,
and I'm sure there are others here, even more experienced than I am, who
can help.
--
Paul Schmehl (pauls at utdallas.edu)
Senior Information Security Analyst
The University of Texas at Dallas
http://www.utdallas.edu/ir/security/
More information about the freebsd-questions
mailing list