Date: Thu, 7 Jun 2001 16:16:07 -0500 From: "Robert Herrold" <bobber@intense.net> To: "Greg Haa" <Greg.Haa@amux.com>, <freebsd-security@FreeBSD.ORG> Subject: Re: Named Message-ID: <002d01c0ef97$238cbce0$6c01a8c0@mpcsecurity.com> References: <2BFD35C3F1F9D31185CE00B0D0202302838707@SUNKING>
next in thread | previous in thread | raw e-mail | index | archive | help
Yes, that's someone trying to exploit your box using a named bug. Looks to me like you're running a <8.2.3 REL of bind. Make sure you're running bind 8.2.3 or later. If you're not, I would recommend you get chkrootkit to verify you haven't been rooted. www.chkrootkit.org Bob Herrold Senior Network Engineer Metropark Communications 10405 A Baur Blvd St Louis MO 63132 (314)439-1900 ----- Original Message ----- From: "Greg Haa" <Greg.Haa@amux.com> To: <freebsd-security@FreeBSD.ORG> Sent: Thursday, June 07, 2001 1:37 PM Subject: Named > So this was in a named.core file. > > AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA>BBBBBBBBBBBBBBBBBBBBBBB > BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB > AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA>BBBBBBBBBBBBBBBBBBBBBB > BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBAAAAAAAAAAAAAAAAAAaa > > or something very similar. Can you tel;l me what this means? > > > -thanks > > greg.haa@amux.com > > To Unsubscribe: send mail to majordomo@FreeBSD.org > with "unsubscribe freebsd-security" in the body of the message > To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?002d01c0ef97$238cbce0$6c01a8c0>