Security Incidents mailing list archives

Re: Linuxconf scanning


From: "St. Arnaud, Jon" <jon.starnaud () RCI COM>
Date: Fri, 25 Aug 2000 10:12:02 -0500

I have to apologize to the list.  When I found that exploit it was tar'd up
with a windows virus and a couple of Unix worms I didn't understand.  I
published the code and got rid of the rest.  Since then I haven't been able
to find the tar file again.

As near as I can remember the tar was described as being a Unix virus but
the source code was definitely for linuxconf.

I have to agree with the publisher though that the source alone does not
work.  The source perhaps takes advantage of linuxconf after a worm has
infected the machine?...

-----Original Message-----
From: Jon Lewis [mailto:jlewis () LEWIS ORG]
Sent: Thursday, August 24, 2000 9:33 PM
To: INCIDENTS () SECURITYFOCUS COM
Subject: Re: Linuxconf scanning


On Thu, 24 Aug 2000 lamont () icopyright com wrote:

Somewhere out there is a response from the Linuxconf author that he
couldn't get that exploit to work and doesn't believe any 6.x version was
vulnerable.  I can't find the response in google though.

That the maintainer can't make published exploit code work doesn't mean a
whole lot.  That large numbers of script kids are scanning, sometimes just
for linuxconf, doesn't mean it's insecure, but it should worry you.

----------------------------------------------------------------------
 Jon Lewis *jlewis () lewis org*|  I route
 System Administrator        |  therefore you are
 Atlantic Net                |
_________ http://www.lewis.org/~jlewis/pgp for PGP public key_________


Current thread: