23 Jul
2012
23 Jul
'12
2:56 p.m.
Mainly just a heads up. Something hit at another site where it appears the hackers installed a "jynx rootkit". It's not clear that is all they did to the system since they kit is a "userland" exploit, but various log files were being found in system directories. /var/log/^^ as an example. Reports indicate that this rootkit is not detected by chkrootkit or rootkithunter. Chances are becuase it impact user levels with a LD_LIBRARY path setting being added to user paths than puts the reality.so library early in the users settings. Not sure you'd see anything from this. It appears to have been an intial target of a glassfish oracle java application service getting toasted. --Gene
5169
Age (days ago)
5169
Last active (days ago)
0 comments
1 participants
participants (1)
-
rackow@anl.gov