Re: any1 stumbled across eCkit ?

From: Ian Jones (ian@dsl081-056-052.sfo1.dsl.speakeasy.net)
Date: Mon Nov 26 2001 - 15:35:36 PST

  • Next message: Blake McNeill: "Re: Malicious use of grc.com"

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    Patrick van Zweden <patrickat_private> writes:
    
    > In /lib/ldd.so/ i found the patch script and a file called td. Strings
    > revealed that it is some kind of testing program but i don't know for sure. 
    
    This is most likely the tfn[2k] daemon. It is used to serve the master
    in a DDoS network. You can read more here:
    
    http://www.cert.org/incident_notes/IN-99-07.html#tfn
    http://packetstorm.decepticons.org/distributed/TFN2k_Analysis.htm
    
    -----BEGIN PGP SIGNATURE-----
    Comment: Keeping the world safe for geeks.
    
    iD8DBQE8AtHIwBVKl/Nci0oRAuNHAJ0UexI3uf6nMBIf8ROfwM2kDUSH3ACfWKZt
    kCRXx8yIa++OuRYhDt2lf6s=
    =Bvru
    -----END PGP SIGNATURE-----
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Mon Nov 26 2001 - 16:54:26 PST