subject: (Fwd) Re: WZAP Exploit
posted: Thu, 18 Jan 2001 12:31:50 -0000



------- Forwarded message follows -------
Date sent: Tue, 16 Jan 2001 22:08:42 -0500
Send reply to: Pheh <[email protected]>
From: Pheh <[email protected]>
Subject: Re: WZAP Exploit
Originally to: Rick King <[email protected]>
To: [email protected]

If a wtmp/utmp editor (zapper) is sitting on your system - a) someone is
trying to hack root on your box who already has an account or b) someone
has root on your box and has been attempting to cover their tracks. Is
the program root owned? If so, you can be 100% sure your box is rooted
and you may as well start a rebuild. Regardless, you should pull your
ethernet connection to the box and scour it.

Now obviously I don't know your exact scenerio, but seeing your @home
email I'm going to go out on a limb. Is this a Red Hat box you have
sitting off a cable modem? Did you bother to run any patches on
it? Understand that if the answers are yes for the former and no for the
latter that you are indirectly contributing to DDoS attacks and providing
jump points for internet hooligans.

Good luck to you.

Wilbur


On Tue, 16 Jan 2001, Rick King wrote:

> I noticed a wzap file in the /var/log directory on my RH 6.1 box today and
> was wondering if someone can give me more information on what kind of
> exploit this is. I know it's a program that allows someone to cover their
> tracks, but that's about it. What kind of problem can this cause in the
> future if it's sitting on my linux box now and what can I do to remove it?
>
>
> Thanks,
> Rick.
>


------- End of forwarded message -------

generated by msg2page 0.06 on Jul 21, 2006 at 19:04:54

 search: