История изменений
Исправление kerneliq, (текущая версия) :
$ ./audit libkeyutils.so.1.9 output
$ strings output |grep -Eo '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}'
78.47.139.110
.. *google a bit*...
$ host mail.rubop.com
mail.rubop.com has address 78.47.139.110
$ whois rubop.com
....
Rgistrant:
Ibragimov
Polanskay 11
Moskow, Russia 11223
RU
70958627014
Domain Name: RUBOP.COM
Administrative Contact:
Ibragimov, Sergey pmadison12@gmail.com
Polanskay 11
Moskow, Russia 11223
RU
70958627014
http://www.reddit.com/r/netsec/comments/18ro3c/sshd_rootkit/
Исходная версия kerneliq, :
$ ./audit libkeyutils.so.1.9 output
$ strings output |grep -Eo '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}'
78.47.139.110
.. *google a bit*...
$ host mail.rubop.com
mail.rubop.com has address 78.47.139.110
$ whois rubop.com
....
Rgistrant:
Ibragimov
Polanskay 11
Moskow, Russia 11223
RU
70958627014
Domain Name: RUBOP.COM
Administrative Contact:
Ibragimov, Sergey pmadison12@gmail.com
Polanskay 11
Moskow, Russia 11223
RU
70958627014