Re: Did I give up on telnet too easily?

From: Nico Kadel-Garcia (nkadel_at_verizon.net)
Date: 09/22/03


Date: Mon, 22 Sep 2003 01:57:19 GMT

Jem Berkes wrote:
>>Is this done commonly by crackers? *OF COURSE* it is, because it's
>>very difficult to detect but easy to do and they can reap a *lot* of
>>passwords from people who are careless.
>
>
> Why go to all this trouble and harvest a bunch of users passwords, when you
> can run a well established exploit and instantly root pretty much any
> university, small web site or clueless company using an ancient but
> unpatched BIND, wu-ftp, sendmail, or (my favourite) RPC install?
>
> Passwords are a dime a dozen.

Because they *are* a dime a dozen with unencrypted services like telnet
for all servers, ftp for non-anonymous users too dumb to use a different
password, and HTTP servers too dumb to use SSL, especially compared to
writing and leaving yourselves more traceable by running remote
exploits. In almost all cases, it's Just Safer(tm) to sniff them than
break into a remote machine that *may* be running a vulnerable version
but may *also* be running good log checkers to trace your little weasel
attack back the source machine.



Relevant Pages

  • Re: Did I give up on telnet too easily?
    ... >>passwords from people who are careless. ... > Why go to all this trouble and harvest a bunch of users passwords, ... writing and leaving yourselves more traceable by running remote ... break into a remote machine that *may* be running a vulnerable version ...
    (comp.os.linux.security)
  • RE: User Passwords
    ... You cannot manage password changes in a NON-domain environment. ... need to access each machine individually or create a batch file to change ... your users passwords. ... can effectively chang ethe user's passwords to what ever you like. ...
    (microsoft.public.win2000.security)
  • Re: PHP, Md5, and password retreival forms..
    ... I hired a guy to help me setup the database. ... but its sending the passwords encrypted. ... is yes (if you fiddle with the form) but you should leave it just as ... your users passwords are, just reset them, that's all they need. ...
    (comp.lang.php)
  • Re: force password change
    ... There's an attribute in AD (mustchchpwd) that needs ... > dsmod to change the AD users passwords per batch, ... > ldiff or csvds to import text/csv files into AD ... > change the passwords this way. ...
    (microsoft.public.windows.server.active_directory)
  • Re: [opensuse] Howto start encrypted machine remotely
    ... There's a remote machine with encrypted /home and /swap. ... During bootup it asks for the passwords - but the machine should be able to startup remotely. ... Buy a console server:( ... ssh as root once the system is booted, and activate the crypto partitions manually from there. ...
    (SuSE)

Loading