Full Disclosure mailing list archives
RE: !SPAM! Automated ssh scanning
From: "Todd Towles" <toddtowles () brookshires com>
Date: Thu, 26 Aug 2004 09:19:18 -0500
That is a worry you should have. But we need to know how they did it before we just assume it. Anyone test it on another linux system? Fedora? -----Original Message----- From: full-disclosure-admin () lists netsys com [mailto:full-disclosure-admin () lists netsys com] On Behalf Of Richard Verwayen Sent: Thursday, August 26, 2004 8:41 AM To: FD Subject: RE: !SPAM! [Full-disclosure] Automated ssh scanning On Thu, 2004-08-26 at 15:12, Todd Towles wrote:
The kernel could be save. But with weak passwords, you are toast. Any
automated tool would test guest/guest.
Hello Todd! You are right about the passwords, but guest is only a unprivileged account as you may have on many prodruction machines. But they managed to become root on this machine due to a kernel(?) exploit! Should I then consider any woody system to be insecure to let people work at? Richard _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- RE: !SPAM! Automated ssh scanning, (continued)
- RE: !SPAM! Automated ssh scanning Ron DuFresne (Aug 26)
- Re: !SPAM! Automated ssh scanning Tremaine (Aug 26)
- Re: !SPAM! Automated ssh scanning Richard Verwayen (Aug 26)
- Re: !SPAM! Automated ssh scanning Jan Luehr (Aug 26)
- RE: !SPAM! Automated ssh scanning Ron DuFresne (Aug 26)
- Re: !SPAM! Automated ssh scanning Barry Fitzgerald (Aug 26)
- Re: !SPAM! Automated ssh scanning Ron DuFresne (Aug 26)
- Re: !SPAM! Automated ssh scanning Jan Luehr (Aug 26)
- Re: !SPAM! Automated ssh scanning Ron DuFresne (Aug 26)
- Re Automated ssh scanning Mister Coffee (Aug 26)
- RE: !SPAM! Automated ssh scanning Ron DuFresne (Aug 26)
- Re: !SPAM! Automated ssh scanning Tremaine (Aug 26)
- Re: !SPAM! Automated ssh scanning Richard Verwayen (Aug 26)
- Re: Automated ssh scanning Matt Zimmerman (Aug 26)
- Re: !SPAM! Automated ssh scanning sec-focus (Aug 26)
- Re: !SPAM! Automated ssh scanning andreas (Aug 27)
- Re: !SPAM! Automated ssh scanning Robert Jaroszuk (Aug 27)
- Re: Automated ssh scanning Matt Zimmerman (Aug 27)
- Re: !SPAM! Automated ssh scanning Chris Adams (Aug 30)