Trojan Found in libpcap and tcpdump | Linux Today

Trojan Found in libpcap and tcpdump

Written By
Web Webster
Web Webster
Nov 14, 2002

[ Thanks to LogError for this link.
]

“Members of The Houston Linux Users Group discovered that the
newest sources of libpcap and tcpdump available from tcpdump.org
were contaminated with trojan code. HLUG has notified the
maintainers of tcpdump.org.

“Details:

  • “The trojan contains modifications to the configure script and
    gencode.c (in libpcap only).
  • The configure script downloads
    http://mars.raketti.net/~mash/services which is then sourced with
    the shell. It contains an embedded shell script that creates a C
    file, and compiles it.
  • The program connects to 212.146.0.34 (mars.raketti.net) on port
    1963 and reads one of three one byte status codes: A – program exits
    D – forks and spawns a shell and does the needed file descriptor
    manipulation to redirect it to the existing connection to
    212.146.0.34.
    M – closes connection, sleeps 3600 seconds, and then
    reconnects…”

Complete
Story

Web Webster

Web Webster

Web Webster has more than 20 years of writing and editorial experience in the tech sector. He’s written and edited news, demand generation, user-focused, and thought leadership content for business software solutions, consumer tech, and Linux Today, he edits and writes for a portfolio of tech industry news and analysis websites including webopedia.com, and DatabaseJournal.com.

Linux Today Logo

LinuxToday is a trusted, contributor-driven news resource supporting all types of Linux users. Our thriving international community engages with us through social media and frequent content contributions aimed at solving problems ranging from personal computing to enterprise-level IT operations. LinuxToday serves as a home for a community that struggles to find comparable information elsewhere on the web.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.