[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [cobalt-users] Hacked!
- Subject: Re: [cobalt-users] Hacked!
- From: "Joe Sullivan" <sullivan83@xxxxxxxx>
- Date: Wed May 23 15:24:08 2001
- List-id: Mailing list for users to share thoughts on Cobalt products. <cobalt-users.list.cobalt.com>
> Hey All,
>
> I am using a RAQ4 and I went in today to turn on the ASP service and when
I
> did, I opened up the parameters for it once it started and I saw the
> following. I am not sure how someone got in there, but they did and i'm
not
> sure what else to check to make sure they didn't put anything into my
system
> for later access, but let me know if anyone has seen this? Also, what do
I
> do to restore the ASP Manager?
>
> Thanks.
>
> Page Title: Kill all the Japanese!
>
> 1i0n Crew
> Powered by c00l ======H.U.C=====1i0n
You might check this page out at
http://www.cert.org/incident_notes/IN-2001-03.html. especially the part
about 'li0n worm'. This sounds like what you are experiencing.
Regards,
Joe Sullivan
www.hyper-techs.com