Focus on Virus
ELF_SSHSCAN.A and ELF_PORTSCAN.A Nov 10 2005 03:03AM
Doug Fox (dfox168 hotmail com) (3 replies)
Re: ELF_SSHSCAN.A and ELF_PORTSCAN.A Nov 11 2005 01:47AM
jayjwa (jayjwa atr2 ath cx)
Re: ELF_SSHSCAN.A and ELF_PORTSCAN.A Nov 10 2005 06:18PM
Stephen J. Smoogen (smooge gmail com)
Not sure that these are viruses. I think they are part of a root-kit
that scans the internet for ssh servers that have bad passwords. I
would consider your RH box to have been compromised somehow until
proven otherwise. The usual suspects would be:

a) the box has guesable passwords that the ssh automated root scanners
found and opened up the box.
b) the box has an unpatched external facing binary that a hacker was
able to take advantage of (HTTP, SSH, email, cgi scripts?) and was
able to upload these onit

On 11/9/05, Doug Fox <dfox168 (at) hotmail (dot) com [email concealed]> wrote:
> Found two files, elf_sshscan.a and elf_portscan.a, compressed in a *.tgz
> file on a Red Hat box. Exported the file to a MS box, Trend Micro
> OfficeSacn detected them as viruses, but did not provide any information
> other than the names in its knowledgebase.
>
> Searched TM site, no information was available today.
>
> Any information of these two viruses, such as how the virus getting on to
> the Red Hat box, etc. are appreciated.
>
> Thanks,
>

--
Stephen J Smoogen.
CSIRT/Linux System Administrator

[ reply ]
Re: ELF_SSHSCAN.A and ELF_PORTSCAN.A Nov 10 2005 05:44PM
Paul Schmehl (pauls utdallas edu)


 

Privacy Statement
Copyright 2010, SecurityFocus