[95205] in RedHat Linux List

home help back first fref pref prev next nref lref last post

Re: port 111

daemon@ATHENA.MIT.EDU (Jan Carlson)
Thu Oct 15 21:25:56 1998

Date: Fri, 16 Oct 1998 01:18:45 +0000
From: Jan Carlson <janc@iname.com>
To: redhat-list@redhat.com
Resent-From: redhat-list@redhat.com
Reply-To: redhat-list@redhat.com

Install the upgrades from ftp.redhat.com.  It's often too busy, try also
ftp://ftp.lame.org/mirrors/redhat/redhat-5.1/updates/i386/

The upgrades solve many security problems, including the nfs one.

Emmanuel Papirakis wrote:

> Hey,
>
>         one of my friends got hacked throw port 111. This port was opened because of his nfs daemon. The problem is that the program /bin/login has been replaced by some sort of fake. Also, finger and who don't show any users, no matter how many virtual consols we are logged on.
>
>         I think this guy has installed some kind of root-kit on his machine. Does anyone know of such root-kit, how they work, how to fix the damage and how to prevent being hacked throw that port?
>
>         Will stopping nfs daemon do the trick? ANd, what if you want to do some nfs, is there a safe way?
>
>                                         Papi
>
> --
>   PLEASE read the Red Hat FAQ, Tips, Errata and the MAILING LIST ARCHIVES!
>                http://www.redhat.com http://archive.redhat.com
>          To unsubscribe: mail redhat-list-request@redhat.com with
>                        "unsubscribe" as the Subject.

--

Jan Carlson
janc@iname.com    Scarborough, Ontario, Canada
Mailed with Netscape 4.07 on Red Hat Linux 5.1





-- 
  PLEASE read the Red Hat FAQ, Tips, Errata and the MAILING LIST ARCHIVES!
		http://www.redhat.com http://archive.redhat.com
         To unsubscribe: mail redhat-list-request@redhat.com with 
                       "unsubscribe" as the Subject.


home help back first fref pref prev next nref lref last post