Rootkit Found
Posted: Tue Dec 31, 2013 11:14 am
Happy New Year guys! Sad to say I'm still working. Sighs*
We found a rootkit on or VICI
Using rkhunter:
Rootkit checks...
Rootkits checked : 321
Possible rootkits: 3
Rootkit names : SHV4 Rootkit, SHV5 Rootkit, Sniffer
We immediately wiped it out. I would like to ask if anyone here have any suggestions on what entries to add at iptables or which ports we need to block in order to prevent this from happening again.
I have browsed around but I couldn't really find an exact article on what I am looking for. Please help.
We found a rootkit on or VICI
Using rkhunter:
Rootkit checks...
Rootkits checked : 321
Possible rootkits: 3
Rootkit names : SHV4 Rootkit, SHV5 Rootkit, Sniffer
We immediately wiped it out. I would like to ask if anyone here have any suggestions on what entries to add at iptables or which ports we need to block in order to prevent this from happening again.
I have browsed around but I couldn't really find an exact article on what I am looking for. Please help.