Re: [Rkhunter-users] SSH backdoor non detected by RKH

2013-06-19 Thread Luigi Rosa
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 unsp...@hushmail.com said the following on 18/06/2013 23:05: On Tue, 18 Jun 2013 17:57:16 +0200 Luigi Rosa The ssh has a different configuration from the standard ssh on port 22 Different how? What's the location of the file(s)? I cannot get

Re: [Rkhunter-users] SSH backdoor non detected by RKH

2013-06-19 Thread William Maddler
Hey, recently Hetzner (www.hetzner.de) found at least one of their boxes was running an undetected sshd backdoor. http://pastie.org/8015553 The malicious code used in the backdoor exclusively infects the RAM. First analysis suggests that the malicious code directly infiltrates running Apache