It looks pretty serious and genuine to me. Once they have the
software running on the network, and you've installed the modified
version of the sshd, they can log into any account, even
administrator, and you won't know they're doing it.

You can always use md5sum to checksum your sshd against a known checksum on a regular basis.

072cdd3aeb3eb8575d0cc155a2e69fa7 /usr/sbin/sshd

This of course assumes that they haven't compromised md5sum, the compiler, something else, or this post to the list :)

Have fun,
Shay
--
=========================== Shay Telfer ================================
Perth, Western Australia Technomancer It must be bunnies!
Opinions for hire [POQ]
[EMAIL PROTECTED] fnord