LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-20-2008, 02:28 PM   #1
b4gi
LQ Newbie
 
Registered: Jan 2008
Posts: 1

Rep: Reputation: 0
Trojan program Backdoor.PHP.C99Shell.p austrumi


Kaspersky AV said:
"detected: Trojan program Backdoor.PHP.C99Shell.p
File: austrumi-1.5.1.iso//BOOT/AUSTRUMI.TGZ;1//austrumi.tar//./var/www/htdocs/cyti/c99.php"
What is mean?!!
 
Old 01-20-2008, 02:38 PM   #2
MS3FGX
LQ Guru
 
Registered: Jan 2004
Location: NJ, USA
Distribution: Slackware, Debian
Posts: 5,852

Rep: Reputation: 361Reputation: 361Reputation: 361Reputation: 361
It means it has found a file which main contain that Trojan...
 
Old 01-20-2008, 04:38 PM   #3
jschiwal
LQ Guru
 
Registered: Aug 2001
Location: Fargo, ND
Distribution: SuSE AMD64
Posts: 15,733

Rep: Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682
I think that file is a webshell.
http://en.wikipedia.org/wiki/Remote_File_Inclusion

It looks like you make a backup of a server that might be compromised.

Last edited by jschiwal; 01-20-2008 at 04:40 PM.
 
Old 01-20-2008, 04:51 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Yeah, it's web-based shell written in PHP giving access to your system. Usually found on compromised boxen. If you need a shell like then it's cool. If anybody uses it to access your system without you knowing then it's obviously not. Weird stuff to put on a "rescue" CD (that's what Austrumi advertises itself as).
 
Old 01-20-2008, 08:35 PM   #5
MS3FGX
LQ Guru
 
Registered: Jan 2004
Location: NJ, USA
Distribution: Slackware, Debian
Posts: 5,852

Rep: Reputation: 361Reputation: 361Reputation: 361Reputation: 361
Did you download this from an official mirror? If you grab something from an unofficial source and don't verify the MD5s, there is no telling what you have.
 
Old 01-21-2008, 12:01 PM   #6
unixfool
Member
 
Registered: May 2005
Location: Northern VA
Distribution: Slackware, Ubuntu, FreeBSD, OpenBSD, OS X
Posts: 782
Blog Entries: 8

Rep: Reputation: 158Reputation: 158
Quote:
Originally Posted by MS3FGX View Post
Did you download this from an official mirror? If you grab something from an unofficial source and don't verify the MD5s, there is no telling what you have.
You might also want to alert the maintainer of the official mirror (they may not know).
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Austrumi Help nathan3 Linux - Distributions 9 12-29-2007 12:27 PM
Austrumi phantom_cyph Linux - Distributions 15 12-29-2007 12:09 PM
BackDoor-CVT Trojan kotty General 4 09-11-2007 12:13 PM
Austrumi jtouso Linux - Distributions 3 05-12-2006 05:06 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:57 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration