attack question

From: Rob (rshahamat_at_hotmail.com)
Date: 09/25/03


Date: Thu, 25 Sep 2003 16:09:56 -0400

It seems someone attacked our sun server:

> prstat

   PID USERNAME SIZE RSS STATE PRI NICE TIME CPU PROCESS/NLWP

 26750 root 976K 784K run 0 0 1:19.46 79% dd/1

> ps -ef | grep 26750

    root 26750 26693 73 13:27:41 ? 79:50 dd if=/dev/zero of=./ARSEX3
bs=1 count=

> ps -ef | grep 26693

    root 26750 26693 79 13:27:41 ? 80:05 dd if=/dev/zero of=./ARSEX3
bs=1 count=

    root 26693 26690 0 13:27:40 ? 0:00 /bin/ksh ./sz /bin/ls bin/ls

we aren't running those commands. so any idea how we can prevent that, also
any idea to see what happend here.

Thanks for any help.

Rob



Relevant Pages

  • Re: CMD prompt problems
    ... >> Hi, Rob. ... Ipconfig and ping work fine for me. ... >> Prompt window? ... Or are you running these commands from the Run ...
    (microsoft.public.windowsxp.perform_maintain)
  • Re: Omitting empty field
    ... Rob ... > MailMergeHelper in the list of commands and drag it to a toolbar or menu ... usually labels or envelopes which are connect ...
    (microsoft.public.word.mailmerge.fields)
  • Re: Declarative USE AFTER question
    ... I agree that adding commands is the ideal... ... should happend if you get some wild error. ... statement has NO commands following it when you get a fatal error? ...
    (comp.lang.cobol)
  • Re: autoexpect on 5.0.7
    ... Rob wrote: ... > I have to tell that I had some problems at first when I started commands ... "exit" terminates the shell, but it doesn't display anything and it ... Tony Lawrence ...
    (comp.unix.sco.misc)
  • RE: Cant issue commands from Command Prompt
    ... these commands are disabled by the firewall,,,go to firewall,, advanced ect ... "Rob" wrote: ...
    (microsoft.public.windowsxp.help_and_support)