> 
> 
> I would delete it, unless you know why it's there.  You may 
> have been compromised, and chances are if the intruder was 
> sloppy enough to leave that file behind then there are 
> probably other signs as well.  Take a look around your box.
 

You could install the lsof rpm and find out what processes are using it.
Have you tried to correlate the date of it's creation with any package
installs you may have done?

---- 
Dean Hall at Tactix ReEngineering ( [EMAIL PROTECTED] ) 
503 520-9699  http://www.tactix.com 
> 

_______________________________________________
cobalt-security mailing list
[EMAIL PROTECTED]
http://list.cobalt.com/mailman/listinfo/cobalt-security

Reply via email to