Bindshell rootkit

Mike Loiterman mike at ascendency.net
Sun Mar 30 10:14:55 PST 2003


 
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Ok...did some checking.  I forgot to mention that I killed dead syslogd.  Not just a -HUP but an actual kill and restarted.  I did this several times.  I was trying to get something else to work.

Anyway, I killed it again this morning and restarted.  The infect message went away immediately.  

Could this have been the problem?

- ------------------------------
Mike Loiterman
grantADLER Medical Corporation
Ph:  630-302-4944
Fax:  773-868-0071
PGP Key 0xD1B9D18E 

-----BEGIN PGP SIGNATURE-----
Version: PGP 8.0
Comment: This message has been digitally signed by Mike Loiterman

iQA/AwUBPoQreGjZbUnRudGOEQKlKQCg3A7qjZeuOR8xRy1Y2mwhPXo1wSkAnji1
/ZHe/l+5pciz+K01oFG0hxwo
=+qca
-----END PGP SIGNATURE-----



More information about the freebsd-security mailing list