[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] Interface Promiscuous Mode and FTP Hacks



after rebooting the RaQ servers, i can see a new process that i think i
never saw before:

/sbin/mgetty -s 115200 -r -b ttyS0

When i try to kill the process, it restarts immediately.

Seems it is a modem access. Note the RaQ patches were installed and BIND
where "off" anyway on those servers.... chkrootkit does not detect
anything (see my last post)

chris