[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [cobalt-users] lastlog on RaQ3
- Subject: Re: [cobalt-users] lastlog on RaQ3
- From: Jens Kristian Søgaard <jens@xxxxxxxxxxxxxxxxxxxx>
- Date: Mon Feb 19 10:41:01 2001
- List-id: Mailing list for users to share thoughts on Cobalt products. <cobalt-users.list.cobalt.com>
Hi all,
> It looks to me like last log is a pointer to the name of the last log
file.
> Mine only has one line in it.
You have a weird logfile then. Normally it's a binary file, and not a
pointer or link.
> > Don't be paranoid.
> I have to disagree here, owning a Raq and posting a message to this list
> increases you chances of being hacked by 1000 fold over the run of the
mill
> linux server.
I don't think so. I don't think that hackers use this list as a way of
finding new servers to hack.
We had a server standing as a spare on the net - it was connected for
approx. 7 days. It wasn't used by anyone, wasn't referenced anywhere.
Anyhow, some hacker got in with a root kit (not the bind bug, but something
else). This hacker got in by scanning a lot of ip addresses.
(I discovered the hack the same day, and the server could then be restored
to normal)
--
Jens Kristian Søgaard, Mermaid Consulting I/S,
jens@xxxxxxxxxxxxxxxxxxxx,
http://www.mermaidconsulting.com/