Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-Virus
[Top] [All Lists]

Re: ELF_SSHSCAN.A and ELF_PORTSCAN.A

Subject: Re: ELF_SSHSCAN.A and ELF_PORTSCAN.A
Date: Thu, 10 Nov 2005 11:18:52 -0700
Not sure that these are viruses. I think they are part of a root-kit
that scans the internet for ssh servers that have bad passwords. I
would consider your RH box to have been compromised somehow until
proven otherwise. The usual suspects would be:

a) the box has guesable passwords that the ssh automated root scanners
found and opened up the box.
b) the box has an unpatched external facing binary that a hacker was
able to take advantage of (HTTP, SSH, email, cgi scripts?) and was
able to upload these onit

On 11/9/05, Doug Fox <dfox168@hotmail.com> wrote:
Found two files, elf_sshscan.a and elf_portscan.a, compressed in a *.tgz
file on a Red Hat box.  Exported the file to a MS box, Trend Micro
OfficeSacn detected them as viruses, but did not provide any information
other than the names in its knowledgebase.

Searched TM site, no information was available today.

Any information of these two viruses, such as how the virus getting on to
the Red Hat box, etc. are appreciated.

Thanks,



--
Stephen J Smoogen.
CSIRT/Linux System Administrator

<Prev in Thread] Current Thread [Next in Thread>