Security Incidents mailing list archives

Re: compromised machine as ASU


From: "Matthew S. Hallacy" <mhallacy () MERCURY XTRATYME COM>
Date: Mon, 18 Sep 2000 00:23:54 -0500

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

I've had personal experience with the people from general*.asu.edu, call
the campus and they will transfer you to the campus police, their network
is -very- insecure, even for a .edu, I suspect all their campus machines
are trojaned, i had 3 people from asu.edu that had accounts on a system of
ours, all three had their account compromised. (on our system and asu).


                        Matthew S. Hallacy
                        XtraTyme Technologies
                        Systems/Network Administrator

On Sat, 16 Sep 2000, fred anger wrote:

Greetings.  I run an OpenBSD machine that provides mail and shell access
to a few of my friends via secure shell.  No telnet nor ftp.  Some users
use imap to check mail, but their logins are disabled.  Anyway, yesterday,
a friend ssh'ed in from a machine at Arizona State University -
general3.asu.edu - checked her email and logged out.  Two minutes later,
another ssh connection from general3.asu.edu was logged, as well as
another login to her account.  I probably wouldn't have noticed, but sudo
sent me a message noting that the user tried to use sudo (I don't have a
sudoers file).  This friend has no idea what sudo is or does, and she's
positive she did not log in twice within 2 minutes yesterday, so I'm
guessing the ssh client on general3.asu.edu has been trojaned and is
logging passwords, and that the 2nd connection was a cracker who owns (at
least) general3.asu.edu.

I have no idea who to contact at ASU regarding this, so if anyone has any
ideas, please let me know.  Thanks.

-fa

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.2 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iD8DBQE5xabxyECZjIgidSERAnByAJ9NVsj7ymquuk+PpEwP7MQvEM9JywCfc/Ft
TeIXYfwNp/9YzjBBy8gi+1A=
=I7yt
-----END PGP SIGNATURE-----


Current thread: