North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

RE: resolved Re: should i publish a list of cracked machines?

  • From: Roeland Meyer
  • Date: Thu Aug 23 19:08:16 2001

|> From: Kevin Houle [mailto:[email protected]]
|> Sent: Thursday, August 23, 2001 10:42 AM
|> 
|> --On Thursday, August 23, 2001 12:39:21 -0400 Jim Mercer 
|> <[email protected]> 
|> wrote:
|> 
|> > my suspicions and some things to look for:
|> >
|> > - boxes were comprimised using the buffer overflow in telnetd
|> > (speculation)
|> 
|> The CERT/CC is aware of some level of automated exploitation of
|> the recently described telnetd vulnerability. If folks have yet
|> to patch systems for that particular vulnerability, it would be
|> a good thing to spend time doing. We've seen it used to deploy
|> DDoS-capable tools, for example.
|> 
|> More info on the vulnerability at:
|> 
|>  http://www.kb.cert.org/vuls/id/745371

quick patch for this vulnerability

#! /bin/sh

rm -f `whereis in.telnetd`
rm -f `whereis in.ftpd`

/etc/rc.d/init.d/ssh-server start