Bug#575784: cron: security hole ? allowes opening user sessions ?

2010-03-29 Thread Oz Nahum
Package: cron Version: 3.0pl1-106 Justification: root security hole Severity: critical Tags: security Hi Guys, I am by no means a security expert. I noticed my server was breached and multiple accounts on it have been logging via cron over and over again. From the auth log: Mar 29 10:30:01

Bug#575784: cron: security hole ? allowes opening user sessions ?

2010-03-29 Thread Javier Fernandez-Sanguino
That logging appears because those users have setup cron jobs and an entry is generated every time a job is started. This is fixed in sid (by not using pam's session-interactive) but does not mean you have been hacked through cron. Regards Javier 2010/3/29, Oz Nahum nahu...@gmail.com: Package:

Bug#575784: cron: security hole ? allowes opening user sessions ?

2010-03-29 Thread Oz Nahum
Hi Javier, Thanks for your message. I've ran a rkhunter on my computer, and it seems like I have a few rootkits in it. So, feel free to close the bug. On Mon, Mar 29, 2010 at 12:28 PM, Javier Fernandez-Sanguino j...@computer.org wrote: That logging appears because those users have setup