Re: [suse-security] Re: Backdoor over http(s)??

Stefan Andreas Tichy wrote:

Complete directory listing, very nice ;-)


Looking there, I downloaded a "lk" file. It is a tar.gz file in reality. It is definitely a rootkit. It contains a new crond, login, ps, etc. If the end result weren't so sickening, this would be exciting (academically speaking).


