Security Incidents mailing list archives

Re: Possible widespread hole?


From: Andreas Östling <andreaso () IT SU SE>
Date: Sun, 27 Aug 2000 15:36:16 +0200

On Sat, 26 Aug 2000 c_patin () HOTMAIL COM wrote:

9704 stream tcp nowait root /bin/sh sh -i
Is this possibly some major hole in a
package that we both installed, or did we just get hacked by
the same person. Seems a little weird to just be
coincidence

9704 is a popular port for exploits to open up a root shell, just as
9088 and good old 1524 for example.


I have since closed the hole, and placed my box behind a
hardware firewall to protect it. 

If "I have since closed the hole" means you just removed the line from
inetd, the real hole is still there.
(A vulnerable version of wu-ftpd or rpc.statd is probably a good guess)
A firewall is not an excuse for not securing the host itself.
Since the machine is already cracked you should reinstall the OS and
apply all security patches and disable all services you don't need.


Andreas Östling


Current thread: