Re: [SLUG] LKM rootkits

From: Glenn Meyer (me@glennmeyer.com)
Date: Thu Feb 27 2003 - 08:54:54 EST


I had several of those for about two weeks, but after searching the
/var/log/maillog carefully for the domain complaining, I found that
there was no email out from my server to that domain - only the incoming
complaints. So I can only guess that someone was spoofing and using my
email address but actually sending from some other machine - then when
the complaining recipient replied, it came to my actual domain.

Rock wrote:
> I would like to know how you knew you had been hacked. I have strange
> emails that I get that say I have sent a virus infected email to someone
> I have never heard of, and from my system at that. I get 2 or 3 of them
> a day.
>
> We have both Linux and NT servers and I have both a Linux and MS
> desktop. We use Nortons on incoming and outgoing email so I don't know
> how that could happen, unless it is sneaking out the Linux side of the
> system.
>
> Michael C. Rock
> Systems Analyst
> Registered Linux User # 287973
>
> "The time has come the walrus said to speak of many things,,,"
> "Christians give up what they cannot keep to gain what they cannot lose"
>
>
>



This archive was generated by hypermail 2.1.3 : Fri Aug 01 2014 - 15:53:59 EDT