
25 Dec
2002
25 Dec
'02
12:18
Hi Matthias,
Huh? Since when can a port be used twice? I'd say "bi" is a tronjaned version of apache and the original apache isn't running at all.
That is what I was wondering too -- but: I killed the prozess "bi", I didn't started anything else - and http and https still working. And: the suse-check showed the added processes - but no removed prozesses. Maybe it's a trojan "trough" apache? And: the port 4000 isn't accessable from the outside -- because there is a separate fw in front of. I have tcpdump-files -- but it's a hard work to check/filter these megabytes to get the right part out of it. Takes some time. Regards, Dirk