[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

statd attach



I've recently seen in the log files of my home and office solaris machines
messages of the sort:

 Jan 25 15:58:34 hopf statd[138]: attempt to create "/var/statmon/sm//../
../../../../../../../../../../../../../../../../../../../../../../../../../../..
/../../../../../../../../../../../../../../../../../../../../../../../../../../.
./../../../../../../../../../../../../../../../../../../../../../../../../../../
../../../..//../../../../../../../../../../../../../../../../../../../../../../.
./../../../../../../../../../../../../../../../../../../../../../../../../../../
../../../../../../../../../../../../../../../../../../../../../../../../../../..
/../../../../../../../../../../../tmp/.nfs09   D   H   $   $   $   $
               `   O *   *   *   *   #   # \174       P *`   c    6
              \175           )               \175         #   #     ;
              #          XbinXsh tirdwr                      "

This was followed by an unauthorized login as root.

Does anyone know about such attacks? Does it apply to openbsd also?

Thanks, Clarence Wilkerson


Visit your host, monkey.org