[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] bind hack



Once upon a time, J. Masterson <masterson@xxxxxxxxxxxx> said:
> Hi, all. Been unsubscribed for a month or so; I'm back now.
> 
> Four Red Hat 6.1 machines (not cobalt boxes) that close friends of mine
> administer were hacked over the weekend, root password compromised,
> /bin/login replaced -- all will likely require a reinstall to be safe. 
> 
> It appears that the problem is with the version of Bind that accompanies
> the OS... Red Hat recommends upgrading to 8.2.2 immediately. It looks
> like my Raq3i has bind-8.2-6C1 installed.
> 
> Do a search for 'admrocks' at deja.com for the specific flavor of hack.
> 
> Any Cobalt reps comment on Raqs' vulnerabilty to this back door?

RTFW.  In particular, http://www.cobalt.com/support/download/raq3.eng.html

Upgrade your RaQ3 with RaQ3-Security-1.1.pkg (been out since December)
or RaQ3E-Update-OS-2.0.pkg which includes this security update (among
others).
-- 
Chris Adams <cmadams@xxxxxxxxxx>
Systems and Network Administrator - HiWAAY Information Services
I don't speak for anybody but myself - that's enough trouble.