Security Incidents mailing list archives
Re: Possible widespread hole?
From: Andreas Östling <andreaso () IT SU SE>
Date: Sun, 27 Aug 2000 15:36:16 +0200
On Sat, 26 Aug 2000 c_patin () HOTMAIL COM wrote:
9704 stream tcp nowait root /bin/sh sh -i Is this possibly some major hole in a package that we both installed, or did we just get hacked by the same person. Seems a little weird to just be coincidence
9704 is a popular port for exploits to open up a root shell, just as 9088 and good old 1524 for example.
I have since closed the hole, and placed my box behind a hardware firewall to protect it.
If "I have since closed the hole" means you just removed the line from inetd, the real hole is still there. (A vulnerable version of wu-ftpd or rpc.statd is probably a good guess) A firewall is not an excuse for not securing the host itself. Since the machine is already cracked you should reinstall the OS and apply all security patches and disable all services you don't need. Andreas Östling
Current thread:
- Possible widespread hole? c_patin (Aug 26)
- Re: Possible widespread hole? Alexander Schreiber (Aug 27)
- Re: Possible widespread hole? An Thi-Nguyen Le (Aug 27)
- Re: Possible widespread hole? Andreas Östling (Aug 27)
- Re: Possible widespread hole? Jon Lewis (Aug 27)
