There is also a documented exploit (see AUSCERT) with an older version of
bind8 with this exact symptom. I think it's a buffer overflow technique.
This happened to me and I only noticed it because I was on the console at
the time and it killed several other processes so I was aware that something
was up. A quick check of my system log indicated that "root" had just
created a new account a few minutes earlier. No other tracks anywhere that I
could see. Scary stuff. I run very few services and I''m not running ftp.
The only two services I could find any problems with were bind8 and ssh both
of which I updated to address known issues.

> RH6.0 had a vulnerable wu-ftpd.  That is the most likely point of access.
> I had it happen to me and there was no evidence as they had cleared the
> logs.  I only became aware because of an upstream filter/router that was
> logging accesses.
>
> Howard.
> ______________________________________________________
> LANNet Computing Associates <http://www.lannet.com.au>
>
> On Mon, 22 May 2000, DaZZa wrote:
>
> > On Mon, 22 May 2000 [EMAIL PROTECTED] wrote:
> >
> > > I realise there are security issues with Redhat 6.0 and will be
installing 6.2
> > > soon. In the meantime, what is the most likely method someone could
use to
> > > inject new userids in the /etc/passwd and /etc/shadow files? There is
no record
> > > of access by telnet, ftp nor anything else.
> >
> > How long is a piece of string?
> >
> > In other words, how much have you secured your machine from the standard
> > install? RH by default is pretty open - lots of services running which
> > aren't really needed, not much tightening of other stuff.
> >
> > There's no way of waving a magic wand and saying "This is how you were
> > hacked".
> >
> > DaZZa
> >
> > --
> > SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
> > To unsubscribe send email to [EMAIL PROTECTED] with
> > unsubscribe in the text
> >
>
> --
> SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
> To unsubscribe send email to [EMAIL PROTECTED] with
> unsubscribe in the text

--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to