|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Subject: Re: Cracked by the Brazilians
From: Ralf Spenneberg (spenneb
UNI-MUENSTER.DE)Date: Fri Mar 31 2000 - 00:00:17 CST
- Next message: Joey McAlerney: "Re: UDP port 9200"
- Previous message: Seth Milder: "Re: Cracked by the Brazilians"
- Next in thread: Seth Milder: "Re: Cracked by the Brazilians"
- Maybe reply: Ralf Spenneberg: "Re: Cracked by the Brazilians"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Hi!
Are you sure that your bind is just listening to the private ethernet card?
The ADMROCKS Attack is quite famous. There were at least three
vulnerabilities in bind 8.2 last year. They might not have made it to to 6.0
updates directory, because 6.1 was the active distribution. And yes, that
one had several bind updates.
Cheers,
Ralf
> Von: Seth Milder <mrseth
PHYSICS.GMU.EDU>
> Antworten an: Seth Milder <mrseth
PHYSICS.GMU.EDU>
> Datum: Thu, 30 Mar 2000 13:22:56 -0500
> An: INCIDENTS
SECURITYFOCUS.COM
> Betreff: Cracked by the Brazilians
>
> Hi.
>
> I am running a Linux server that is running RH 6.0. I have implemented
> TCP wrappers, portsentry, logcheck and religiously applied any patches
> as soon as possible. Still, I get cracked. My server runs Bind-8.2
> (caching nameserver only, which is bound to an ethernet card with
> private addresses), PostgreSQL, NFS, ssh2 (no root login allowed),
> ipop3d, and NIS. It also serves as a IP MASQ server for a computer lab
> through a second ethernet card. I found the usual BitchX stuff along
> with the package bscan.tar which contains:
>
>
> I guess this may have something to do with this:
> [root
physics ADMROCKS]# pwd
> /var/named/ADMROCKS
>
- Next message: Joey McAlerney: "Re: UDP port 9200"
- Previous message: Seth Milder: "Re: Cracked by the Brazilians"
- Next in thread: Seth Milder: "Re: Cracked by the Brazilians"
- Maybe reply: Ralf Spenneberg: "Re: Cracked by the Brazilians"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]