Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 24 Jun 1996 20:05:05 +0300 (EET DST)
From:      Narvi <narvi@haldjas.folklore.ee>
To:        Terry Lambert <terry@lambert.org>
Cc:        "Jordan K. Hubbard" <jkh@time.cdrom.com>, guido@gvr.win.tue.nl, hackers@FreeBSD.ORG, security@FreeBSD.ORG, ache@FreeBSD.ORG
Subject:   Re: I need help on this one - please help me track this guy down!
Message-ID:  <Pine.BSF.3.91.960624195743.25097C-100000@haldjas.folklore.ee>
In-Reply-To: <199606240651.XAA27306@phaeton.artisoft.com>

next in thread | previous in thread | raw e-mail | index | archive | help


On Sun, 23 Jun 1996, Terry Lambert wrote:

> > Hmmm.  We have reason to believe that he *didn't* get root (though
> > we're still assuming he did, just to be paranoid) and if the mod times
> > can be trusted, hosts.equiv hasn't been touched in many months (and
> > localhost is commented out).
> 
> 1)	Do not believe this.  Assume he got root.
> 2)	Assume your password changes are mailed out as cleartext by
> 	your passwd program.
> 3)	Assumed md5 and checksum have been hacked to lie about
> 	themselves and any other files affected.
> 4)	Assume system time stamps were changed.
> 5)	Assume all log files were edited.
> 6)	Best approach: reinstall the system (from distribution,
> 	not backup --- no telling how long he was there).
> 7)	Turn off the stupid "password must meet these criteria"
> 	on the password change.  All it does is reduce the search
> 	space a hacker needs to apply.
> 8)	Put spoofing filters on your firewall; basically, look for
> 	the response bit.
> 9)	Make sure you aren't running routed -q.
> 10)	Turn of source routing on your gateway, if it's on.

Now are there some more things someone who's  system was breaked into
could look for? Perhaps some passwords should be switched to S/Key - 
it should be possible to generate them on a remote machine and then
install?

> 
> If you need help getting the FBI involved, tell them you had "munitions"
> on the machine.  ;-).

The "secure" part of distribution + DES actually are so by the definition,
no matter that he could have downloaded them from much nearer...

	Sander

who is by no means a security specialist

> 
> 
> 					Terry Lambert
> 					terry@lambert.org
> ---
> Any opinions in this posting are my own and not those of my present
> or previous employers.
> 



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.3.91.960624195743.25097C-100000>