Re: Strange Apache log and mambo security - sexy executable

2006-01-23 Thread Edward Shornock
Oops...didn't trim enough of the response and curiosity made me research this. According to the sophos site: --cut-- Linux/Rst-B will attempt to infect all ELF executables in the current working directory and the directory /bin If Linux/Rst-B is executed by a privileged user then it may attempt

Re: Strange Apache log and mambo security - sexy executable

2006-01-23 Thread Edward Shornock
On Mon, Jan 23, 2006 at 08:31:40AM +0100, Maik Holtkamp wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > Hi, > > yesterday morning I found a strange entry in my apache log files (debian > sarge, apache 1.3, mambo 4.5.3, kernel 2.4.31). It's a dyndns homelan > Server, just serving my F