From: | Neil Conway <neilc(at)samurai(dot)com> |
---|---|
To: | Justin Clift <justin(at)postgresql(dot)org> |
Cc: | The Hermit Hacker <scrappy(at)postgresql(dot)org>, pgsql-www(at)postgresql(dot)org, PostgreSQL Advocacy and Marketing Mailing List <pgsql-advocacy(at)postgresql(dot)org> |
Subject: | Re: [pgsql-www] FW: (AUSCERT ESB-2003.0563) CERT Advisory CA-2003-21 |
Date: | 2003-08-14 06:18:39 |
Message-ID: | 20030814061839.GJ76772@home.samurai.com |
Views: | Raw Message | Whole Thread | Download mbox | Resend email |
Thread: | |
Lists: | pgsql-advocacy |
On Thu, Aug 14, 2003 at 02:09:32PM +0800, Justin Clift wrote:
> Wu-FTPd has probably the worst track record on the planet for FTP
> vulnerabilities.
Actually, the cracker didn't even use an ftpd security hole,
apparently:
-----
A root compromise and a Trojan horse were discovered on gnuftp.gnu.org,
the FTP server of the GNU project. The machine appears to have been
cracked in March 2003, but we only discovered the crack in the last week
of July 2003. The modus operandi of the cracker shows that (s)he was
interested primarily in using gnuftp to collect passwords and as a
launching point to attack other machines. It appears that the machine was
cracked using a ptrace exploit by a local user immediately after the
exploit was posted.
(For the ptrace bug, a root-shell exploit was available on 17 March 2003,
and a working fix was not available on linux-kernel until the following
week. Evidence found on the machine indicates that gnuftp was cracked
during that week.)
-----
Besides, this is OT for this list anyway.
-Neil
From | Date | Subject | |
---|---|---|---|
Next Message | Chris Phelan | 2003-08-14 06:28:04 | Re: Draft #6: Semi-Final |
Previous Message | Justin Clift | 2003-08-14 06:09:32 | Re: [pgsql-www] FW: (AUSCERT ESB-2003.0563) CERT Advisory CA-2003-21 |