[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] RAQ2 - HELP! HTTPD Won't Start, missing "home" directory?



As long as you're willing to trust that no one did anything else malicious on your server while they were in there. A favorite, but by no means sole exploit, is to change the "operator" user to have root privileges (no I won't say how on an open list, but believe me lots of people already know; it's not rocket science) and give it a password you know. Then you can get back in at any time and do anything.

When was the last time you checked the rights and passwords of all your users <frown>?

Rebuilding the box is safest whenever you've experienced (or think you've experienced) a crack.

Jeff

At 03:20 AM 2/1/00  Rickard Osser wrote:
Actually, if you just rebuild the directory structure under the
admin-user, which is kind of straight forward ( it looks like any user
directory) then you can continue as if nothing happened, the "?" file is
ReMovable..

--
Jeff Lasman, nobaloney.net
<jblists@xxxxxxxxxxxxx>
<www.nobaloney.net>, <www.mailtraqna.com>, <www.email-lists.com>