Analysis of the Linux backdoor used in Freenode IRC network compromise
nccgroup.com
nccgroup.com
> Whilst the handshake and data security mechanisms are
> arguably well designed the persistence mechanism isn’t in
> any sense stealthy. This particular rootkit would be
> easily detectible using tools as Tripwire and Rootkit
> Hunter.
Say the persistence mechanism wasn't there. How would you go about detecting this rootkit?Then again, the best course of action is to pull that server down and build a new clean box, and do all the analysis offline. Boot from some sort of read-only media to minimize the threat, and analyze from a known good kernel, making sure to not run anything from the infected box unless you're goddamn sure what you're doing.
From my understanding of the article, it was a rootkit, rather than a pre-existing backdoor. So it would have been something that was installed after a system had been penetrated using other exploits.
The MD5's you want are specific to the kit used to attack their client and would disclose the effectiveness of their response and investigation to an attacker,and are also not much good to anyone else. In the Disqus comments the author offers to provide them on request from legitimate researchers.
This is a standard precaution, not at all bogus, and it is great that they were able to share as much as they did for general use.