[95112] in RedHat Linux List
port 111
daemon@ATHENA.MIT.EDU (Emmanuel Papirakis)
Thu Oct 15 08:25:32 1998
Date: Thu, 15 Oct 1998 08:24:27 -0400 (EDT)
From: Emmanuel Papirakis <Emmanuel_Papirakis@UQTR.UQuebec.CA>
To: redhat-list@redhat.com
Resent-From: redhat-list@redhat.com
Reply-To: redhat-list@redhat.com
Hey,
one of my friends got hacked throw port 111. This port was opened because of his nfs daemon. The problem is that the program /bin/login has been replaced by some sort of fake. Also, finger and who don't show any users, no matter how many virtual consols we are logged on.
I think this guy has installed some kind of root-kit on his machine. Does anyone know of such root-kit, how they work, how to fix the damage and how to prevent being hacked throw that port?
Will stopping nfs daemon do the trick? ANd, what if you want to do some nfs, is there a safe way?
Papi
--
PLEASE read the Red Hat FAQ, Tips, Errata and the MAILING LIST ARCHIVES!
http://www.redhat.com http://archive.redhat.com
To unsubscribe: mail redhat-list-request@redhat.com with
"unsubscribe" as the Subject.