[100535] in RedHat Linux List

home help back first fref pref prev next nref lref last post

Re: Hacked! :(

daemon@ATHENA.MIT.EDU (David E. Fox)
Sat Nov 21 16:21:36 1998

From: "David E. Fox" <dfox@belvdere.vip.best.com>
To: sharding@oregon.uoregon.edu
Date: Sat, 21 Nov 1998 13:19:35 -0800 (PST)
Cc: redhat-list@redhat.com
Reply-To: dfox@belvdere.vip.best.com
In-Reply-To: <Pine.SGI.4.02.9811211307450.23339-100000@gutenberg.uoregon.edu> from "Sean Harding" at Nov 21, 98 01:08:58 pm
Resent-From: redhat-list@redhat.com

> Not particularly. Any cracker who values his own time won't bother trying
> to decrypt passwd entries. Time is better spent using a dictionary attack
> program, such as Crack...

Exactly. Speaking of password entries, this perp put two entries in
/etc/passwd which I removed. Also I went through /etc/passwd and noticed
some obvious things, like no password for www and http accounts, so
I locked them.

And, telnet & rlogin services are disabled here for a while...

> sean
------------------------------------------------------------------------
David E. Fox                 Tax              Thanks for letting me
dfox@belvdere.vip.best.com   the              change magnetic patterns
root@belvedere.sbay.org      churches         on your hard disk.
-----------------------------------------------------------------------


-- 
  PLEASE read the Red Hat FAQ, Tips, Errata and the MAILING LIST ARCHIVES!
		http://www.redhat.com http://archive.redhat.com
         To unsubscribe: mail redhat-list-request@redhat.com with 
                       "unsubscribe" as the Subject.


home help back first fref pref prev next nref lref last post