FOLLOW-UP: Hacked?

From: David <davide_at_picasso.nmr.ucsf.edu>
Date: Fri Jul 13 2001 - 15:03:29 EDT
I'm sorry, just found the document I was looking for 2 minutes after
sending the email. Look like this is my case:

http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D2894

Patches are not yet available, so I'll disable the service for now.

Thanks

David

---------- Original message ----------
Subject: Hacked?

Hi all,
	I got a few messages like the following one:

Jul 13 07:22:35 xxx bsd-gw[3653]: Invalid protocol request (66):
BBBXXXXXXXXXXXXXXXXXX%.208u%300$n%.235u%301$n%.255u%302$n%.192u%303$n111F1f1C]C]KMM1ECf]fE'MEEEMCCC1?A^u1FEMU/bin/sh

I scanned the sun site, cert and sans but I couldn't find a lot of
informations about it. I also checked a lot of binaries with the SUN
fingerprint database and nothing seems changed. Does anyone know more
about this?

Thanks

David
Received on Fri Jul 13 20:03:29 2001

This archive was generated by hypermail 2.1.8 : Wed Mar 23 2016 - 16:24:59 EDT