Hello People!
I have been fighting a security breach for a while now and have learned a lot about how to track down the places where scrpt kiddies deposit stuff. It appears most of the stuff involves IRC junk. Anyway, apart from my frustration, I have learned a lot but I came across something that was really suprising this morning. I searched from possible cron jobs and this came up:
/usr/local/directadmin/customapache/dovecot-1.0.0/doc/wiki/__/.../.../.../iroffer.cron
Also, these patchs are in play:
/usr/local/directadmin/customapache/dovecot-1.0.0/doc/wiki/__/.../.../.../obj/iroffer_dccchat.o
/usr/local/directadmin/customapache/dovecot-1.0.0/doc/wiki/__/.../.../.../src/iroffer_headers.h
So, I guess the question is this... is there any reason at all that this would be a part of the dovecot installation? I think not... but I wanted to verify with some of you gurus out there. I find it odd that there would be a wiki directory anyway within this area... but the other deeply embedded directories look suspicious. Also, how could they have gotten into the customapache directory under directadmin?
Please advise... I appreciate it a lot!!!
I have been fighting a security breach for a while now and have learned a lot about how to track down the places where scrpt kiddies deposit stuff. It appears most of the stuff involves IRC junk. Anyway, apart from my frustration, I have learned a lot but I came across something that was really suprising this morning. I searched from possible cron jobs and this came up:
/usr/local/directadmin/customapache/dovecot-1.0.0/doc/wiki/__/.../.../.../iroffer.cron
Also, these patchs are in play:
/usr/local/directadmin/customapache/dovecot-1.0.0/doc/wiki/__/.../.../.../obj/iroffer_dccchat.o
/usr/local/directadmin/customapache/dovecot-1.0.0/doc/wiki/__/.../.../.../src/iroffer_headers.h
So, I guess the question is this... is there any reason at all that this would be a part of the dovecot installation? I think not... but I wanted to verify with some of you gurus out there. I find it odd that there would be a wiki directory anyway within this area... but the other deeply embedded directories look suspicious. Also, how could they have gotten into the customapache directory under directadmin?
Please advise... I appreciate it a lot!!!