Skip site navigation (1)Skip section navigation (2)
Date:      01 Jun 2001 16:23:09 +0200
From:      Dag-Erling Smorgrav <des@ofug.org>
To:        Brian Behlendorf <brian@collab.net>
Cc:        "Karsten W. Rohrbach" <karsten@rohrbach.de>, <freebsd-security@FreeBSD.ORG>
Subject:   Re: Apache Software Foundation Server compromised, resecured. (fwd)
Message-ID:  <xzpvgmguvn6.fsf@flood.ping.uio.no>
In-Reply-To: <Pine.BSF.4.31.0105311838200.52261-100000@localhost>
References:  <Pine.BSF.4.31.0105311838200.52261-100000@localhost>

next in thread | previous in thread | raw e-mail | index | archive | help
Brian Behlendorf <brian@collab.net> writes:
> The shell machine at SF didn't have reverse DNS (or at least it wasn't
> recorded in the wtmp), so you might want to look for 216.136.171.252 (the
> machine our friend came in from) or maybe even 216.136/24.

I hope you meant 216.136.171/24, and not 216.136/16:

des@des ~% host freefall.freebsd.org
freefall.freebsd.org has address 216.136.204.21
freefall.freebsd.org mail is handled (pri=10) by hub.freebsd.org

Oh, and .252 does have reverse DNS:

des@des ~% host 216.136.171.252
252.171.136.216.IN-ADDR.ARPA domain name pointer usw-sf-fw2.sourceforge.net

DES
-- 
Dag-Erling Smorgrav - des@ofug.org

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?xzpvgmguvn6.fsf>