On Fri, 24 Aug 2007 21:32:07 +0200 Jürgen Fricke <[EMAIL PROTECTED]> 
wrote:
>i found a file called java on my cobalt box.
A totally stripped ELF. Nice one. 

>I think it is a malware like suckit.
FUCK: Can't open /dev/kmem for read/write (13)
+++ Program exited with code 1 +++
Yes, looks like it, thanks for sharing.

Was it running? If so, any process details like lsof? How did you 
get this?


Regards, unSpawn

--
Get paid for your creativity.  Click here for information on graphic software 
training.
http://tagline.hushmail.com/fc/Ioyw6h4dFyczoOdez7cCp2m69TLmSca4Qo2OM3vYGJBWc85c4QYHSY/



-------------------------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc.
Still grepping through log files to find problems?  Stop.
Now Search log events and configuration files using AJAX and a browser.
Download your FREE copy of Splunk now >>  http://get.splunk.com/
_______________________________________________
Rkhunter-users mailing list
Rkhunter-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/rkhunter-users

Reply via email to