Beefy Boxes and Bandwidth Generously Provided by pair Networks
Perl: the Markov chain saw
 
PerlMonks  

Re^2: ACKKKKKKKKK! I Have been cracked!

by tadman (Prior)
on Apr 03, 2001 at 18:18 UTC ( [id://69311]=note: print w/replies, xml ) Need Help??


in reply to Re: ACKKKKKKKKK! I Have been cracked!
in thread ACKKKKKKKKK! I Have been cracked!

As an aside that is hopefully not too OT, one of the boxes here was cracked once. It was all because of a simple (human) error. POP3/FTP passwords are sent plaintext, and so the system was configured to have different passwords for POP3/FTP from the system accounts. Unfortunately, due to laziness, I suppose, one of the admins set their password to be the same for both and later logged in from home to check their mail.

A few days later, our box was cracked with an off-the-shelf "root kit". Even though we were using SSH, they were able to "sniff" the POP3 password over their cable modem and then log in using SSH, use SUDO, and have their way with our system.

Thankfully the 'haX0r' only ran some sort of IRC bot or relay program and didn't do any real damage.

Always make sure that your POP3 and FTP passwords are not the same as your SSH login! Especially for users with 'sudo' access!
  • Comment on Re^2: ACKKKKKKKKK! I Have been cracked!

Replies are listed 'Best First'.
Re: Re^2: ACKKKKKKKKK! I Have been cracked!
by isotope (Deacon) on Apr 03, 2001 at 20:50 UTC
    Actually, I'd recommend having completely separate accounts for sudo (only used off-site in emergencies, otherwise on-site only), with RSA authentication only. Keep the email on a separate, private, non-privileged account.

    --isotope
    http://www.skylab.org/~isotope/

Log In?
Username:
Password:

What's my password?
Create A New User
Domain Nodelet?
Node Status?
node history
Node Type: note [id://69311]
help
Chatterbox?
and the web crawler heard nothing...

How do I use this?Last hourOther CB clients
Other Users?
Others studying the Monastery: (6)
As of 2024-04-18 21:38 GMT
Sections?
Information?
Find Nodes?
Leftovers?
    Voting Booth?

    No recent polls found