Re: Found, a new rootkit



On Friday 31 March 2006 19:29, John Summerfield wrote:
Gene Heskett wrote:
We've cut our bandwidth use in half by getting rid of that. We also
checked the logs and added several dozen more addresses
to /etc/hosts.deny,

That is fairly useless. IP addresses of attackers change as quickly at
IP addressess of spammers, and they have so many it's like trying to
fence off the porn sites of the world.

More important is to discover how the rogue gained entry and to close
that loophole. How did the shell script get there? Whose account was
used? Does .bash_history include useful clues about what was done? Did
the attacker send email after gaining entry? If so, the recipent
domain (eg Yahoo) may be interested.

Root's account, eh? Disallow password-based authentication for root.
Ensure that only those who need it have shell accounts, and that those
have good passwords. _I_ have incoming ssh land on my personal
desktop, there there is only my password to worry about.

root ssh is denied. To do normal maintainance we log in as ourselves &
su -.

--
Cheers, Gene
People having trouble with vz bouncing email to me should add the word
'online' between the 'verizon', and the dot which bypasses vz's
stupid bounce rules. I do use spamassassin too. :-)
Yahoo.com and AOL/TW attorneys please note, additions to the above
message by Gene Heskett are:
Copyright 2006 by Maurice Eugene Heskett, all rights reserved.

--
fedora-list mailing list
fedora-list@xxxxxxxxxx
To unsubscribe: https://www.redhat.com/mailman/listinfo/fedora-list



Relevant Pages

  • Re: FW: Trace of 139 attack?
    ... /complex—Forces passwords to have a mixture of upper ... > the admin account on local logins (physical security ... >> deleting the logs he cannot do it. ... >> ur Server ur logs will ...
    (Focus-Microsoft)
  • Re: Account Lockout
    ... > will cache passwords for network resources on the local ... When the users logs in...it tries to use those ... >> domain policy says they have 5 retries before account ... This is not a new feature in Windows XP, but has been part of the Windows NT ...
    (microsoft.public.win2000.security)
  • Re: Cant login in to XP
    ... files (in an Administrator - level account) to a pen-drive from your ... When my XP system boots, it asks me for a user password. ... these passwords were left blank. ... or the Admin account, it says the user is logging in, but logs it ...
    (microsoft.public.windowsxp.general)
  • Re: Cant login in to XP
    ... files (in an Administrator - level account) to a pen-drive from your ... When my XP system boots, it asks me for a user password. ... these passwords were left blank. ... or the Admin account, it says the user is logging in, but logs it ...
    (microsoft.public.windowsxp.general)
  • Re: Account lockouts
    ... for reusable passwords and the AAA infrastructures that rely upon them? ... In that context, account lockout policy -- duration, threshold, lockout ... > cracking attacks. ...
    (microsoft.public.security)