-----Original Message-----
From: cobalt-users-admin@xxxxxxxxxxxxxxx
[mailto:cobalt-users-admin@xxxxxxxxxxxxxxx]On Behalf Of Bruce Timberlake
Sent: Monday, February 24, 2003 9:03 PM
To: cobalt-users@xxxxxxxxxxxxxxx
Subject: Re: [cobalt-users] chkrootkit
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
> Yes I did. But then I did delete some of the files in /tmp and
> that cleared the LKM messages about hidden processes. I thought
> slapper only infected MS database products? Any suggestions?
Slapper is the Apache-SSL worm...
You're thinking of the recent SlaMMer (aka Sapphire) worm... :)
- --
Bruce Timberlake
Well I ran chkrootkit again this morning and recieved all the original
warnings again so deleteting the tmp files is not doing the trick. Is it
best to just dump the box and start over with it? I'm not sure how we can
do this, it is a radius,mail,web server for about 1900 customers. I'm not
sure how we can bring it down even for 5 minutes let alone a OS restore and
setup the sites again. I can hear the phone lines ringing already :(
_____________________________________
cobalt-users mailing list
cobalt-users@xxxxxxxxxxxxxxx
To subscribe/unsubscribe, or to SEARCH THE ARCHIVES, go to:
http://list.cobalt.com/mailman/listinfo/cobalt-users
--
This message has been scanned for viruses and
dangerous content by MailScanner, and is
believed to be clean.