From owner-freebsd-security Tue Nov 13 9:55: 8 2001 Delivered-To: freebsd-security@freebsd.org Received: from axel.truedestiny.net (b76168.upc-b.chello.nl [212.83.76.168]) by hub.freebsd.org (Postfix) with ESMTP id B126937B416; Tue, 13 Nov 2001 09:54:57 -0800 (PST) Received: from localhost (localhost [127.0.0.1]) by axel.truedestiny.net (Postfix) with ESMTP id EB52849A24; Tue, 13 Nov 2001 18:54:55 +0100 (CET) Received: by axel.truedestiny.net (Postfix, from userid 1000) id D127649A23; Tue, 13 Nov 2001 18:54:52 +0100 (CET) Date: Tue, 13 Nov 2001 18:54:52 +0100 From: Axel Scheepers To: John Baldwin Cc: Stefan Probst , Rob Hurle , freebsd-security@FreeBSD.ORG Subject: Re: Adore worm Message-ID: <20011113185452.B19098@mars.thuis> Reply-To: Axel Scheepers References: <5.1.0.14.2.20011114000437.02050a70@MailServer> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.2.5i In-Reply-To: ; from jhb@FreeBSD.org on Tue, Nov 13, 2001 at 09:22:33AM -0800 X-Virus-Scanned: by AMaViS perl-10 Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org Hi, Best thing to do is to 'pull the plug' immediately (your net connection). Backup up the machine for later inspection, then reinstall fBSD and if you got a seprate data backup put that back. Then you might put the previous made backup on a clean machine for inspection. Usual vulnerable things like telnet, ftp etc. is a good place to start looking for in your logs. (In case you didn't block them) Gr, Axel On Tue, Nov 13, 2001 at 09:22:33AM -0800, John Baldwin wrote: > X-Mailer: XFMail 1.4.0 on FreeBSD > Date: Tue, 13 Nov 2001 09:22:33 -0800 (PST) > From: John Baldwin > To: Stefan Probst > Subject: RE: Adore worm > Cc: Rob Hurle , freebsd-security@FreeBSD.ORG > > > On 13-Nov-01 Stefan Probst wrote: > > Good Evening, > > > > sorry for newbie-posting, but I don't have too much time to sift through > > archives.... > > > > Looks like my FreeBSD 4.2 Box (FreeBSD 4.2-RELEASE (GENERIC)) got hit by a > > worm - or infested by purpose: > > It's a rootkit, and your box has been compromised. Backup your data and > reinstall unless someone else has a better idea. > > -- > > John Baldwin -- http://www.FreeBSD.org/~jhb/ > "Power Users Use the Power to Serve!" - http://www.FreeBSD.org/ > > To Unsubscribe: send mail to majordomo@FreeBSD.org > with "unsubscribe freebsd-security" in the body of the message -- Axel Scheepers UNIX System Administrator email: axel@axel.truedestiny.net ascheepers@vianetworks.nl http://axel.truedestiny.net/~axel ------------------------------------------ "I can't complain, but sometimes I still do." -- Joe Walsh ------------------------------------------ To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message