najpierw irssi teraz bitchx?
Łukasz J. Mozer
baseciq-news at europa.fcp.edu.pl
Mon Jul 1 19:45:56 CEST 2002
Witajcie.
A few hours ago (1 AM US/Eastern time, July 1) we downloaded
ircii-pana-1.0c19.tar.gz from ftp.bitchx.com (216.165.191.5) and
reviewed the configure script before running it. It has essentially
the same configure backdoor as fragroute-1.2.tar.gz[1] -- a TCP
connection is made outbound, with a shell bound to it (a reverse
telnet). This appears to retry/respawn once per hour. The 1.0c19
tarball at ftp.irc.org (which mirrors bitchx.com) did not appear to be
trojaned when we pulled from there about an hour later.
http://online.securityfocus.com/archive/1/280009/2002-06-28/2002-07-04/0
Za bugtraq && pl.irc
--
=m=>[jack_] że ja niby się znam na linuksie
[jack_!jack at pe38.bydgoszcz.sdi.tpnet.pl] Bo się znasz :)
baseciq at baseciq.org | http://www.baseciq.org/ | LJM5-RIPE
More information about the pld-devel-pl
mailing list