Re: [botnets] mech config captured today

2007-11-17 Thread Radoslav Bodó
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- he? .. i relly didn't understand. my english is so poor on essays ;( b J. Oquendo napsal(a): bodik wrote: yes, i was a ssh bruteforce. user installed oracle client recently, and forget to change a password ;(( it was

[botnets] mech config captured today

2007-11-16 Thread bodik
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- Hi, we've found one instance of bot from someone called Drow (tools were compiled but not stripped somewhere in /home/drow ... ;))). Probably a spanish speaking person. Undernet admins should take a look down below and check

Re: [botnets] mech config captured today

2007-11-16 Thread Steven Adair
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- Just taking a wild stab in the dark, I'd bet on SSH brute force. A number of groups on Undernet (Romanian ones especially) are known to SSH brute force attack boxes and then install mech and put up a bunch of clones in an

Re: [botnets] mech config captured today

2007-11-16 Thread J. Oquendo
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] --bodik wrote: yes, i was a ssh bruteforce. user installed oracle client recently, and forget to change a password ;(( it was oracle:oracle After all this time I don't know how come stupid administrators are given access to

Re: [botnets] mech config captured today

2007-11-16 Thread bodik
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- yes, i was a ssh bruteforce. user installed oracle client recently, and forget to change a password ;(( it was oracle:oracle bodik Adriel Desautels wrote: How did they get in? Regards, Adriel T. Desautels