>
> which begs the question about how they got in....
>
> Which distro, kernel, etc, etc
>
>sounds like the sort of thing everyone needs to know
>>
>> It appears on my system they may have done something with Bind.
>> It went offline at the same time that the attack occured.
>>
I am guessing they exploited bind, since it has been in the news of most
recent months. And I wonder if its a Redhat machine, I am guessing it might.
<plug>
With this all happening around us, I feel pretty happy with myself, as none
of my systems I have built and rolled out to this date have been exploited
for any sort of access.
Just for those interested, I use Debian, although I did start my linux days
out on Slackware over 6 years ago.
</plug>
Cheers
--
SLUG - Sydney Linux User Group Mailing List - http://slug.org.au/
More Info: http://slug.org.au/lists/listinfo/slug