Security Incidents mailing list archives

Update: other depts attacked


From: filipg () FW GEOLOGY PITT EDU (Filip M. Gieszczykiewicz)
Date: Sun, 9 Jan 2000 22:03:46 -0500


Ok, I spoke with a grad student from Physics and he said
he has received attacks from ALL of our dept's machines.
He contacted the University "folks" back on Jan 2nd with
no response (wow, surprise) and decided that as long as
his machines were safe, who cares. Drat. I wish he came
over and bitched... at least I would looking into this
and not wait until my machine was attacked on the 8th!

All solaris machines have been compromised. Since telnet
and ftp rule around here, I _think_ one of the faculty's
IRIX machine was compromised FIRST (runs 5.3 - GAG!) and
once they had a sniffer on that, the Titanic had struck
the iceberg.

I bitched about this last time we got cracked, back in
July-Aug - some of you made choking sounds when I stated
the IRIX version that time too - and you-guessed-it
nothing at all was done.

Ok, my machine is secure. I finally tracked down a grad
student and asked him to yank the net connection on the
3 main servers. The IRIX is locked in an inaccessible
office... rooted, of course.

Deja-vu.

Deja-vu.

Deja-vu.

Deja-vu.

Around and around and around until I wanna puke.

Time to have a chat with the dean.

Cheers,
Filip G.


Current thread: