<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: &#8220;sexygurl&#8221; rootkit hack</title>
	<link>http://mindfulmusings.net/weblog/2003/09/30/sexygurl-rootkit-hack/</link>
	<description>Code, love, life, peace and dogs!</description>
	<pubDate>Fri, 21 Nov 2008 06:59:52 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: phreak</title>
		<link>http://mindfulmusings.net/weblog/2003/09/30/sexygurl-rootkit-hack/#comment-480</link>
		<dc:creator>phreak</dc:creator>
		<pubDate>Mon, 01 Mar 2004 16:46:17 +0000</pubDate>
		<guid>http://mindfulmusings.net/weblog/2003/09/30/sexygurl-rootkit-hack/#comment-480</guid>
		<description>why are you against that hacker you shuold suport
him</description>
		<content:encoded><![CDATA[<p>why are you against that hacker you shuold suport<br />
him</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://mindfulmusings.net/weblog/2003/09/30/sexygurl-rootkit-hack/#comment-140</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Fri, 19 Dec 2003 20:27:16 +0000</pubDate>
		<guid>http://mindfulmusings.net/weblog/2003/09/30/sexygurl-rootkit-hack/#comment-140</guid>
		<description>twa</description>
		<content:encoded><![CDATA[<p>twa</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: German Carrasco</title>
		<link>http://mindfulmusings.net/weblog/2003/09/30/sexygurl-rootkit-hack/#comment-871</link>
		<dc:creator>German Carrasco</dc:creator>
		<pubDate>Wed, 31 Dec 1969 19:00:00 +0000</pubDate>
		<guid>http://mindfulmusings.net/weblog/2003/09/30/sexygurl-rootkit-hack/#comment-871</guid>
		<description>hahaha .... cute</description>
		<content:encoded><![CDATA[<p>hahaha &#8230;. cute</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DAIM50</title>
		<link>http://mindfulmusings.net/weblog/2003/09/30/sexygurl-rootkit-hack/#comment-978</link>
		<dc:creator>DAIM50</dc:creator>
		<pubDate>Wed, 31 Dec 1969 19:00:00 +0000</pubDate>
		<guid>http://mindfulmusings.net/weblog/2003/09/30/sexygurl-rootkit-hack/#comment-978</guid>
		<description>SEXGURL</description>
		<content:encoded><![CDATA[<p><span class="caps">SEXGURL</span></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kamran</title>
		<link>http://mindfulmusings.net/weblog/2003/09/30/sexygurl-rootkit-hack/#comment-1711</link>
		<dc:creator>kamran</dc:creator>
		<pubDate>Wed, 31 Dec 1969 19:00:00 +0000</pubDate>
		<guid>http://mindfulmusings.net/weblog/2003/09/30/sexygurl-rootkit-hack/#comment-1711</guid>
		<description>boy&#038;girl</description>
		<content:encoded><![CDATA[<p>boy&#38;girl</p>
]]></content:encoded>
	</item>
</channel>
</rss>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">

<head profile="http://gmpg.org/xfn/1">
	<title>Mindful Musings &raquo; &#8220;sexygurl&#8221; rootkit hack</title>

	<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
	<meta name="generator" content="WordPress 2.2.3" /> <!-- leave this for stats -->

	<style type="text/css" media="screen">
			@import url( http://mindfulmusings.net/weblog/wp-layout-single.css );
		</style>

	<link rel="stylesheet" type="text/css" media="print" href="http://mindfulmusings.net/weblog/print.css" />
	<link rel="alternate" type="application/rss+xml" title="RSS 2.0" href="http://mindfulmusings.net/weblog/feed/" />
	<link rel="alternate" type="text/xml" title="RSS .92" href="http://mindfulmusings.net/weblog/feed/rss/" />
	<link rel="alternate" type="application/atom+xml" title="Atom 0.3" href="http://mindfulmusings.net/weblog/feed/atom/" />

	<link rel="pingback" href="http://mindfulmusings.net/weblog/xmlrpc.php" />
    	<link rel='archives' title='May 2008' href='http://mindfulmusings.net/weblog/2008/05/' />
	<link rel='archives' title='March 2008' href='http://mindfulmusings.net/weblog/2008/03/' />
	<link rel='archives' title='January 2008' href='http://mindfulmusings.net/weblog/2008/01/' />
	<link rel='archives' title='September 2007' href='http://mindfulmusings.net/weblog/2007/09/' />
	<link rel='archives' title='August 2007' href='http://mindfulmusings.net/weblog/2007/08/' />
	<link rel='archives' title='July 2007' href='http://mindfulmusings.net/weblog/2007/07/' />
	<link rel='archives' title='May 2007' href='http://mindfulmusings.net/weblog/2007/05/' />
	<link rel='archives' title='April 2007' href='http://mindfulmusings.net/weblog/2007/04/' />
	<link rel='archives' title='March 2007' href='http://mindfulmusings.net/weblog/2007/03/' />
	<link rel='archives' title='February 2007' href='http://mindfulmusings.net/weblog/2007/02/' />
	<link rel='archives' title='January 2007' href='http://mindfulmusings.net/weblog/2007/01/' />
	<link rel='archives' title='November 2006' href='http://mindfulmusings.net/weblog/2006/11/' />
	<link rel='archives' title='October 2006' href='http://mindfulmusings.net/weblog/2006/10/' />
	<link rel='archives' title='September 2006' href='http://mindfulmusings.net/weblog/2006/09/' />
	<link rel='archives' title='August 2006' href='http://mindfulmusings.net/weblog/2006/08/' />
	<link rel='archives' title='July 2006' href='http://mindfulmusings.net/weblog/2006/07/' />
	<link rel='archives' title='June 2006' href='http://mindfulmusings.net/weblog/2006/06/' />
	<link rel='archives' title='May 2006' href='http://mindfulmusings.net/weblog/2006/05/' />
	<link rel='archives' title='April 2006' href='http://mindfulmusings.net/weblog/2006/04/' />
	<link rel='archives' title='March 2006' href='http://mindfulmusings.net/weblog/2006/03/' />
	<link rel='archives' title='February 2006' href='http://mindfulmusings.net/weblog/2006/02/' />
	<link rel='archives' title='January 2006' href='http://mindfulmusings.net/weblog/2006/01/' />
	<link rel='archives' title='December 2005' href='http://mindfulmusings.net/weblog/2005/12/' />
	<link rel='archives' title='November 2005' href='http://mindfulmusings.net/weblog/2005/11/' />
	<link rel='archives' title='October 2005' href='http://mindfulmusings.net/weblog/2005/10/' />
	<link rel='archives' title='September 2005' href='http://mindfulmusings.net/weblog/2005/09/' />
	<link rel='archives' title='August 2005' href='http://mindfulmusings.net/weblog/2005/08/' />
	<link rel='archives' title='July 2005' href='http://mindfulmusings.net/weblog/2005/07/' />
	<link rel='archives' title='May 2005' href='http://mindfulmusings.net/weblog/2005/05/' />
	<link rel='archives' title='April 2005' href='http://mindfulmusings.net/weblog/2005/04/' />
	<link rel='archives' title='March 2005' href='http://mindfulmusings.net/weblog/2005/03/' />
	<link rel='archives' title='February 2005' href='http://mindfulmusings.net/weblog/2005/02/' />
	<link rel='archives' title='January 2005' href='http://mindfulmusings.net/weblog/2005/01/' />
	<link rel='archives' title='December 2004' href='http://mindfulmusings.net/weblog/2004/12/' />
	<link rel='archives' title='November 2004' href='http://mindfulmusings.net/weblog/2004/11/' />
	<link rel='archives' title='October 2004' href='http://mindfulmusings.net/weblog/2004/10/' />
	<link rel='archives' title='September 2004' href='http://mindfulmusings.net/weblog/2004/09/' />
	<link rel='archives' title='August 2004' href='http://mindfulmusings.net/weblog/2004/08/' />
	<link rel='archives' title='July 2004' href='http://mindfulmusings.net/weblog/2004/07/' />
	<link rel='archives' title='June 2004' href='http://mindfulmusings.net/weblog/2004/06/' />
	<link rel='archives' title='May 2004' href='http://mindfulmusings.net/weblog/2004/05/' />
	<link rel='archives' title='April 2004' href='http://mindfulmusings.net/weblog/2004/04/' />
	<link rel='archives' title='March 2004' href='http://mindfulmusings.net/weblog/2004/03/' />
	<link rel='archives' title='February 2004' href='http://mindfulmusings.net/weblog/2004/02/' />
	<link rel='archives' title='January 2004' href='http://mindfulmusings.net/weblog/2004/01/' />
	<link rel='archives' title='December 2003' href='http://mindfulmusings.net/weblog/2003/12/' />
	<link rel='archives' title='November 2003' href='http://mindfulmusings.net/weblog/2003/11/' />
	<link rel='archives' title='October 2003' href='http://mindfulmusings.net/weblog/2003/10/' />
	<link rel='archives' title='September 2003' href='http://mindfulmusings.net/weblog/2003/09/' />
	<link rel='archives' title='August 2003' href='http://mindfulmusings.net/weblog/2003/08/' />
	<link rel='archives' title='July 2003' href='http://mindfulmusings.net/weblog/2003/07/' />
	<link rel='archives' title='June 2003' href='http://mindfulmusings.net/weblog/2003/06/' />
	<link rel='archives' title='May 2003' href='http://mindfulmusings.net/weblog/2003/05/' />
			<link rel="EditURI" type="application/rsd+xml" title="RSD" href="http://mindfulmusings.net/weblog/xmlrpc.php?rsd" />

<style type='text/css'>
.hilite {
	color: #fff;
	background-color: #f93;
}
</style>
<meta name="robots" content="index,follow" />
<meta name="page-topic" content="all, alle" />
<meta name="distribution" content="global" />
<meta name="revisit-after" content="1 days" />
<meta name="rating" content="all" />
<meta http-equiv="content-language" content="" />
<meta name="description" content="" />
<meta name="keywords" content=", " />
</head>

<body>
<div id="rap">
<h1 id="header"><a href="http://mindfulmusings.net/weblog">Mindful Musings</a></h1>
<br/>
<div id="content">

 
<h2>9/30/2003</h2>
<div class="post">
<div style="clear:both; float: left; margin-top:-5px;padding-top: 40px; padding-right: 20px;">
<script type="text/javascript"><!--
google_ad_client = "pub-2951450649862551";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text_image";
google_ad_channel = "";
//-->
</script>
<script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
</div>
	 <h3 class="storytitle" id="post-121"><a href="http://mindfulmusings.net/weblog/2003/09/30/sexygurl-rootkit-hack/" rel="bookmark" title="Permanent Link: &#8220;sexygurl&#8221; rootkit hack">&#8220;sexygurl&#8221; rootkit hack</a></h3>
	<div class="meta">Filed under: <ul class="post-categories">
	<li><a href="http://mindfulmusings.net/weblog/category/hackingphreaking/" title="View all posts in Hacking/Phreaking" rel="category tag">Hacking/Phreaking</a></li></ul> &#8212; Mark @ 7:46 pm </div>

	<div class="storycontent">
			<p>:?::mad::???:Found out today at school that a bunch of Sun workstations have been hacked by an rpcbind vulerability which affects portmapper in Solaris 8 and 9. The hack is pretty simple and can be conducted through available scripts on <span class="caps">IRC</span> and on the internet. I have traced the hacked back to a machine in Cincinnati using Fuse Internet Service. They are behind a very stateful firewall and are difficult to track down. My <span class="caps">IDS</span> system logged interactions between that IP and a bunch of Sun OS machines on campus (through suspicious ports and the like), so we have concrete proof and we are in the process of following up with the <span class="caps">ISP</span>. I hate script kiddies! They got in through this vulnerability and installed a very old rootkit (of sexygurl fame), replaced a bunch of files in /usr/bin etc. <span class="caps">OK I</span> got sidetracked looking for information. Anyways, the actual fault, in my humble opinion, lies with Sun. They released a patch for the sadmin vulnerability in question, but it failed to show up on their critical ptach list till the 15th of september. Moral of the story? If you are on an always on connection and want a secure system, cron patch jobs every other day or setup an auto-update schedule through Windoze, you will suffer if you slack!</p>
 	</div>
	<div class="feedback">
                        <br/>
	</div>

	<!--
	<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
				xmlns:dc="http://purl.org/dc/elements/1.1/"
				xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">
			<rdf:Description rdf:about="http://mindfulmusings.net/weblog/2003/09/30/sexygurl-rootkit-hack/"
    dc:identifier="http://mindfulmusings.net/weblog/2003/09/30/sexygurl-rootkit-hack/"
    dc:title="&#8220;sexygurl&#8221; rootkit hack"
    trackback:ping="http://mindfulmusings.net/weblog/2003/09/30/sexygurl-rootkit-hack/trackback/" />
</rdf:RDF>	-->


<!-- You can start editing here. -->

<h2 id="comments">5 Comments 
<a href="#postcomment" title="Leave a comment">&raquo;</a>
</h2>
<p>The <acronym title="Uniform Resource Identifier">URI</acronym> to TrackBack this entry is: <em>http://mindfulmusings.net/weblog/2003/09/30/sexygurl-rootkit-hack/trackback/</em></p>


<ol id="commentlist">
	<li id="comment-140">
	<p>twa</p>
			Comment by Anonymous 12/19/2003 @ 3:27 pm				
		</p>
	</li>

	<li id="comment-480">
	<p>why are you against that hacker you shuold suport<br />
him</p>
			Comment by phreak 3/1/2004 @ 11:46 am				
		</p>
	</li>

	<li id="comment-871">
	<p>hahaha &#8230;. cute</p>
			Comment by <a href='http://unknown.linuxcorp.net' rel='external nofollow'>German Carrasco</a> 6/23/2004 @ 4:14 am				
		</p>
	</li>

	<li id="comment-978">
	<p><span class="caps">SEXGURL</span></p>
			Comment by <a href='http://SORY' rel='external nofollow'>DAIM50</a> 7/15/2004 @ 5:40 am				
		</p>
	</li>

	<li id="comment-1711">
	<p>boy&#38;girl</p>
			Comment by kamran 2/13/2005 @ 5:37 am				
		</p>
	</li>

</ol>
<p><a href='http://mindfulmusings.net/weblog/2003/09/30/sexygurl-rootkit-hack/feed/'><abbr title="Really Simple Syndication">RSS</abbr> feed for comments on this post.</a></p>

<h2 id="postcomment">Leave a comment</h2>
<p>Line and paragraph breaks automatic, e-mail address never displayed, <acronym title="Hypertext Markup Language">HTML</acronym> allowed: <code>&lt;a href=&quot;&quot; title=&quot;&quot;&gt; &lt;abbr title=&quot;&quot;&gt; &lt;acronym title=&quot;&quot;&gt; &lt;b&gt; &lt;blockquote cite=&quot;&quot;&gt; &lt;code&gt; &lt;em&gt; &lt;i&gt; &lt;strike&gt; &lt;strong&gt; </code></p>
<div style="text-align:center;">
<script type="text/javascript"><!--
google_ad_client = "pub-2951450649862551";
google_ad_width = 728;
google_ad_height = 90;
google_ad_format = "728x90_as";
google_ad_type = "text_image";
google_ad_channel = "";
//-->
</script>
<script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
</div>

<form action="http://mindfulmusings.net/weblog/wp-comment-review.php" method="post" id="commentform">
	<p>
	  <input type="text" name="author" id="author" class="textarea" value="" size="28" tabindex="1" />
	   <label for="author">Name</label> (required)	<input type="hidden" name="comment_post_ID" value="121" />
	<input type="hidden" name="redirect_to" value="/weblog/2003/09/30/sexygurl-rootkit-hack/feed/" />
	<input type="hidden" name="comment_reply_ID" value="0" />
	</p>

	<p>
	  <input type="text" name="email" id="email" value="" size="28" tabindex="2" />
	   <label for="email">E-mail</label> (required)	</p>

	<p>
	  <input type="text" name="url" id="url" value="" size="28" tabindex="3" />
	   <label for="url"><acronym title="Uniform Resource Identifier">URI</acronym></label>
	</p>

	<p>
	  <label for="comment">Your Comment</label>
	<br />
	  <textarea name="comment" id="comment" cols="70" rows="4" tabindex="4"></textarea>
	</p>

	<p>
	  <input name="submit" type="submit" tabindex="5" value="Preview" />
	</p>
</form>

</div>
</div>

<!-- Begin Text-Link-Ads code -->
<center>
</center>
<!-- End Text-Link-Ads code -->

<!-- Begin WLTC network code -->
<p class="network" style="margin-left:30px;margin-right:30px;">
	<ul style="list-style-type: none;text-align: center; font: 0.7em Georgia, serif;padding: 0.75em 0 0.75em; margin: 1em 0 1em; background: #F8F7EF;border: 1px dashed #B2B2B2; border-width: 1px 0;">
		<h4>WLTC network sites</h4>
	<li><a href="http://qlue.in">Qlue.in</a>: Blogging Co-Op</li>
        <li><a href="http://findmeacure.com">FindMeACure</a>: Alternative medication and therapy advice from the most trusted resource I have, my father</li>
	<li><a href="http://jobsearchingblog.com/">Job Searching Blog</a>: Find new and interesting jobs and other tidbits on your job search</li>
	<li><a href="http://desidalal.wltc.net">Desidalal</a>: A daily collection of links for amazing prices and deals on online purchases</li>
	<li><a href="http://greencar.us">Greencar</a>: A green but tired old Mazda Miata, energy efficient cars, fuel cells, hybrid tech and more</li>
	<li><a href="http://mindfulmusings.net/hitched">Gittin Hitched</a>: Getting married? Feel the weirdness creeping in? Follow us along our hallowed path</li>
	<li><a href="http://weblogtoolscollection.com">WeblogToolsCollection</a>: Weblog Tools, Wordpress, reviews, opinion, blogs and the economy of blogs.</li>
	<li><a href="http://mindfulmusings.net/weblog">Mindful Musings</a>: A daily log in the life and love of Mark Ghosh</li>
	</ul>
</p>
<!-- End WLTC network code -->

</div>
<!-- Start of StatCounter Code -->
<script type="text/javascript">
<!-- 
var sc_project=936742; 
var sc_invisible=0; 
var sc_partition=7; 
var sc_security="32885268"; 
//-->
</script>

<script type="text/javascript" src="http://www.statcounter.com/counter/counter_xhtml.js"></script><noscript><div class="statcounter"><a 
class="statcounter" href="http://www.statcounter.com/"><img class="statcounter" 
src="http://c8.statcounter.com/counter.php?sc_project=936742&java=0&security=32885268&invisible=0" alt="best tracker" /></a></div></noscript>
<!-- End of StatCounter Code -->
 </body>
</html>
