Gentoo Archives: gentoo-security

From: Javier Barrio <coder@×××××.org>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] Strange occurrence of sendmail and disk I/O in background....
Date: Tue, 19 Feb 2008 12:19:29
Message-Id: 20080219131453.6ff25af1@jbarrio.inet.s2k
In Reply to: [gentoo-security] Strange occurrence of sendmail and disk I/O in background.... by "Christopher P. Kern"
1 > I found vulnerabilities associated with a lower version of
2 > sendmail but none with the version I've installed right now.
3 >
4 > Any suggestions, ideas, or explanations are welcomed.
5
6 It seems you could be owned by someone, maybe due to a combination of a
7 web-app vulnerability which led to an apache shell which led to a
8 kernel exploit execution, which led to root, which led to executing
9 whatever, in that case, making your machine to be a spammer zombie or
10 so. You know, the usual shit nowadays.
11
12 Run the usual tools, chkrootkit, rkhunter, etc.
13
14 Good luck.
15 --
16 echo "dpefsAgmv{p/psh" | perl -pe 's/(.)/chr(ord($1)-1)/ge'
17 GnuPG key ID 0x6D2FF8B5 @ pgp.rediris.es
18 http://www.fluzo.org/
19 <º ))))><

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-security] Strange occurrence of sendmail and disk I/O in background.... Michael W Spitzer <mwspitzer@×××××.com>