atom feed12 messages in org.freebsd.freebsd-securitysequences in the auth.log
FromSent OnAttachments
Sandor BertaAug 13, 2004 7:05 am 
Dan LangilleAug 13, 2004 7:14 am 
Nikolaj I. PotaninAug 13, 2004 7:14 am 
Mohacsi JanosAug 13, 2004 7:15 am 
Jan MuentherAug 13, 2004 7:55 am 
Craig EdwardsAug 13, 2004 10:48 am 
Peter C. LaiAug 13, 2004 11:52 am 
Gregory KuhnAug 13, 2004 12:35 pm 
JustinAug 17, 2004 9:01 pm 
Allen/Gore/SlackWareWolfAug 17, 2004 9:39 pm 
Nikolay PavlovAug 18, 2004 2:54 am 
Devon H. O'DellAug 18, 2004 2:56 am 
Subject:sequences in the auth.log
From:Jan Muenther (jan.@nruns.com)
Date:Aug 13, 2004 7:55:39 am
List:org.freebsd.freebsd-security

Heya,

this is probably the same piece of malware that has been discussed on f-d recently. The username/password combination guest and test are hardcoded into a little statically linked binary which is commonly used together with a SYN scanner.

Chances are good these attempts are coming from a compromised box - you may want to look into that if it is in your realms.

If you need more info, I disassembled them both and made a quick analysis, check the f-d archives.

Cheers, J.