Great Circle Associates Firewalls
(April 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: CERT Advisory - wuarchive ftpd Trojan Horse
From: alastair @ cadence . com (Alastair Young)
Date: Wed, 6 Apr 1994 14:11:37 -0800
To: "Justus J. Addiss (addiss @ hsi . com) 203-949-6414" <addiss @ hsi . com>
Cc: firewalls @ greatcircle . com

At  4:45 PM 4/6/94 -0400, Justus J. Addiss (addiss @
 hsi .
 com) 203-949-6414 wrote:
>>> At  1:56 PM 4/6/94 -0400, Christopher Klaus wrote:
>>> >> 
>>> >Yikes.  Here is something you might want to take fast action against.
>>> >
>>> >I wish CERT would have posted more details though.
>>> >like how the trojan worked or where it was or what sites
>>> >contained copy of it.  how do i know the newest version
>>> >2.3 has no already been modified?
>>> >
>>> 
>>> Check your source for the string '"NULL"' ie the word NULL in double quotes.
>>> 
>>> We have an older version (2.1a) which appears to be clean.
>>> 
>
>Does "NULL" mean you're clean or dirty? How about NULL (no quotes around
>it)?

NULL with quotes around means you are dirty. This appears in the bit of
code that Christopher Klaus just posted.

You could probably do a strings on your binaries and grep for NULL as a
double check. Can't verify that this'll work but its worth a try. Certainly
if the grep comes up with anything then you've been done.

Al

---------------------------------------------------------------------------
Alastair Young                                     _ 2 Ariel NH Red Hunters
Cadence Design Systems, Information Services     )/___     _  
555 River Oaks Parkway, 4B1                    __/(___)_*##/c 56 Red Menace 
San Jose CA 95134         Fax: (408)894-3487  / /\\|| \ /  \ 
alastair @
 cadence .
 com           (408)428-5278  \__/ ----'\__/ 49 TwinportKit
---------------------------------------------------------------------------
These statements and opinions are mine, not those of Cadence Design Systems


Indexed By Date Previous: Re: system()
From: Adam Shostack <adam @ bwh . harvard . edu>
Next: Re: system()
From: Frederick M Avolio <avolio @ tis . com>
Indexed By Thread Previous: Re: CERT Advisory - wuarchive ftpd Trojan Horse
From: "Justus J. Addiss (addiss @ hsi . com) 203-949-6414" <addiss @ hsi . com>
Next: digital pathways
From: lacoursj @ uprc . com (Jeffrey D. LaCoursiere)

Google
 
Search Internet Search www.greatcircle.com