OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Devdas Bhagat (devdasWORLDGATEIN.NET)
Date: Mon Apr 02 2001 - 12:53:54 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    On Mon, 02 Apr 2001, Jonathan Rickman spewed into the ether:
    > > It seems that my previous posts were unclear. I am talking about a remote,
    > > non-privileged DoS. No local console, no root access, no floppy access, no
    > > power-switch access, no hammer handy.
    It is very well known that it is very hard to defend against a
    legitimate user with a shell.
     
    > reboot. You could always just unleash the beast again once he reboots. If
    > an attacker is that focused on completely wrecking a system, he'll just
    > wait for the next Lion/Ramen/<insert l33t w0rm> and toss that at it...get
    > a root shell and rm -rf /
    Nope, the smart kiddie (oxymoron?) will put in knark (or equivalent),
    and modify lots of files (including a crontab that kills off a random
    server every few hours, with a signal 11, and when the server is
    restarted, a random file is deleted/modified or another server dies).

    rm -rf * is much simpler to deal with.

    > That'll keep the admin busy for hours.
    Implement my idea, and the poor admin will be busy for weeks trying to
    figure out what is happenign

    Devdas Bhagat

    --
    Good leaders being scarce, following yourself is allowed.