Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Question, possible danger ssh #572

Open
Idlefase opened this issue May 31, 2022 · 0 comments
Open

Question, possible danger ssh #572

Idlefase opened this issue May 31, 2022 · 0 comments

Comments

@Idlefase
Copy link

Hey there,

Yesterday I successfully built the Linux VM but found something on my host that concerns me.

When I rebooted and ran netstat, I found that a couple of w/o servers were contacted. Mostly fastly OSCP servers and domains called Warsaw. infra and graveyard. infra

I ran rk hunter and detected that Permitrootlogin in the ssh config was set to undefined and there was a hidden .java file in /etc/

The Warsaw and graveyard domains ran over the 5000 port range.

Are these domains legit or am I PWN'D

And could it be that some HTTP:// URI in the build.sh script have been Sniffed on?

Would love to hear from you.

Cheers.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant