Re: Debian Investigation Report after Server Compromises

From: Colin Watson (cjwatson_at_debian.org)
Date: 12/09/03

  • Next message: Kent West: "Re: Virtual PC 5.2"
    Date: Tue, 9 Dec 2003 14:03:43 +0000
    To: debian-user@lists.debian.org
    
    

    On Mon, Dec 08, 2003 at 05:25:38PM -0800, Karsten M. Self wrote:
    > on Mon, Dec 08, 2003 at 11:13:07PM +0000, Colin Watson (cjwatson@debian.org) wrote:
    > > My understanding is that the developer's account on the machine in
    > > question had been disused for some time, and that the machine wasn't
    > > very well-maintained. It could have been any one of a dozen local root
    > > exploits that have been known for some time. I think they investigated,
    > > but the results weren't particularly earth-shaking.
    >
    > Any indication of whether or not this was a local system or a remote
    > system?

    I don't quite understand the question, sorry. If you mean local/remote
    with respect to the developer, I believe it was remote.

    -- 
    Colin Watson                                  [cjwatson@flatline.org.uk]
    -- 
    To UNSUBSCRIBE, email to debian-user-request@lists.debian.org 
    with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
    

  • Next message: Kent West: "Re: Virtual PC 5.2"

    Relevant Pages

    • Re: Local System Account & Network Access
      ... helpful and Roger's suggestion to use local service instead of local system ... account on a domain computer. ... membership but they do have a bearing on what a user/computer has access ... Logon ID: ...
      (microsoft.public.security)
    • Re: How to remote access Windows XP Pro computer?
      ... you happen to use Norton Internet Security please read the following link. ... link for the remote person to access their system. ... "Is LogMeIn secure and what is SSL? ... separate passwords to access both your LogMeIn account and your Target ...
      (microsoft.public.windowsxp.work_remotely)
    • Re: RWW and Remote desktop stopped working on all clients
      ... After diggin through ALL the group policies, I found Remote ... Desktop DISABLED under the Account Lockout policy - I don't think I've even ... adminsitrator or another account with Domain Admin role; also the server ...
      (microsoft.public.windows.server.sbs)
    • Re: DomainLocalServer$ is not a valid user
      ... I have traced by SQL-profiler on remote computer. ... it's always traced the user account. ... Its Security is ... to use the current user credential to logon to the remote server. ...
      (microsoft.public.sqlserver.security)
    • Network share as a Publishing Point source
      ... Give the common user appropriate permissions on folders, ... publishing points, ... >original account would keep me from mapping a publishing ... >>>I tried setting up a remote share for WM9 Services, ...
      (microsoft.public.windowsmedia.server)