BugTraq
Apache hacks (./atac, d0s.txt) Apr 29 2005 07:03PM
Andrew Y Ng (ayn AndrewNg com) (10 replies)
Re: Apache hacks (./atac, d0s.txt) May 01 2005 03:11AM
a.list.address (at) gmail (dot) com [email concealed] (a list address gmail com) (1 replies)
Re: Apache hacks (./atac, d0s.txt) May 02 2005 09:35PM
Nick Bright (nick-tech terraworld net)
Re: Apache hacks (./atac, d0s.txt) Apr 30 2005 07:46AM
Chris Umphress (umphress gmail com)
Re: Apache hacks (./atac, d0s.txt) Apr 30 2005 07:17AM
Sagiko (sagiko gmail com)
Re: Apache hacks (./atac, d0s.txt) Apr 30 2005 04:48AM
Daniel Cid (danielcid yahoo com br)
Re: Apache hacks (./atac, d0s.txt) Apr 30 2005 01:55AM
Luiz Henrique (luizhwk inf ufsc br)
Re: Apache hacks (./atac, d0s.txt) Apr 29 2005 11:33PM
Skip Carter (skip taygeta com)

> My server has been seeing some usual activities today, I don't have much ti=
> me
> to get down to the bottom of things, but after I investigated briefly I have
> decided to disable PERL executable permission for www-data (Apache process's
> user), also locked /var/tmp so www-data cannot write to it.=20

> I found a bunch of processes called ./atac 20 running, and found the
> following content in /tmp/atac:

Running 'strings' on atac reveals that it does an ssh brute force login
attack on remote systems. Interesting enough, our security logs last
night showed such an attempt against some of our clients systems, with
EXACTLY the same sequence of trial user names! So you have a copy of
the tool that was being used against them.

Skip

--
Dr. Everett (Skip) Carter Phone: 831-641-0645 FAX: 831-641-0647
Taygeta Network Security Services email: skip (at) taygeta (dot) net [email concealed]
1340 Munras Ave., Suite 314 WWW: http://www.taygeta.net/
Monterey, CA. 93940

[ reply ]
Re: Apache hacks (./atac, d0s.txt) Apr 29 2005 11:21PM
Robert Zilbauer (zilbauer slappy org)
Re: Apache hacks (./atac, d0s.txt) Apr 29 2005 09:49PM
Jay D. Dyson (jdyson treachery net)
Re: Apache hacks (./atac, d0s.txt) Apr 29 2005 09:45PM
KF (lists) (kf_lists digitalmunition com)
Re: Apache hacks (./atac, d0s.txt) Apr 29 2005 09:36PM
Steve Kemp (steve steve org uk)


 

Privacy Statement
Copyright 2010, SecurityFocus