[95205] in RedHat Linux List
Re: port 111
daemon@ATHENA.MIT.EDU (Jan Carlson)
Thu Oct 15 21:25:56 1998
Date: Fri, 16 Oct 1998 01:18:45 +0000
From: Jan Carlson <janc@iname.com>
To: redhat-list@redhat.com
Resent-From: redhat-list@redhat.com
Reply-To: redhat-list@redhat.com
Install the upgrades from ftp.redhat.com. It's often too busy, try also
ftp://ftp.lame.org/mirrors/redhat/redhat-5.1/updates/i386/
The upgrades solve many security problems, including the nfs one.
Emmanuel Papirakis wrote:
> Hey,
>
> one of my friends got hacked throw port 111. This port was opened because of his nfs daemon. The problem is that the program /bin/login has been replaced by some sort of fake. Also, finger and who don't show any users, no matter how many virtual consols we are logged on.
>
> I think this guy has installed some kind of root-kit on his machine. Does anyone know of such root-kit, how they work, how to fix the damage and how to prevent being hacked throw that port?
>
> Will stopping nfs daemon do the trick? ANd, what if you want to do some nfs, is there a safe way?
>
> Papi
>
> --
> PLEASE read the Red Hat FAQ, Tips, Errata and the MAILING LIST ARCHIVES!
> http://www.redhat.com http://archive.redhat.com
> To unsubscribe: mail redhat-list-request@redhat.com with
> "unsubscribe" as the Subject.
--
Jan Carlson
janc@iname.com Scarborough, Ontario, Canada
Mailed with Netscape 4.07 on Red Hat Linux 5.1
--
PLEASE read the Red Hat FAQ, Tips, Errata and the MAILING LIST ARCHIVES!
http://www.redhat.com http://archive.redhat.com
To unsubscribe: mail redhat-list-request@redhat.com with
"unsubscribe" as the Subject.