[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: [cobalt-users] Powered by H.U.C. ---The 1in0n Crew - HaQ - Much Pain
- Subject: RE: [cobalt-users] Powered by H.U.C. ---The 1in0n Crew - HaQ - Much Pain
- From: "newsgroups" <newsgroups@xxxxxxxxxxxxxxxxxxx>
- Date: Mon Apr 9 18:41:19 2001
- List-id: Mailing list for users to share thoughts on Cobalt products. <cobalt-users.list.cobalt.com>
My sympathies to you Joe. Mine was hacked too a week ago Thursday, same
Crackers. Still recovering and bleeding green. I'd like to know if anyone
else had this same crack too. Some feedback on this would be nice. So far
all I can tell is they do a mass replace of any index/default pages with the
kill a the ***** title tag and replacement html page. I am not experienced
enough to poke around any further. I have tarred up the whole thing post
attack for later analysis (much later).
Here is what I have done to protect my RaQ4 thus far, any other suggestions
would be appreciated:
Disabled Telnet
Installed Open SSH 2.5.1
(Trying) to get SSL to work for POP and SendMail (Pop works ok, SMTP does
not.)
Restricted IPs for service ssH in hosts.deny file
Looking for a Win32 sFTP client to interact with the sFTP service of
openSSH.
-----Original Message-----
From: cobalt-users-admin@xxxxxxxxxxxxxxx
[mailto:cobalt-users-admin@xxxxxxxxxxxxxxx]On Behalf Of J. Ambrose
Sent: Monday, April 09, 2001 3:10 PM
To: cobalt-users@xxxxxxxxxxxxxxx
Subject: [cobalt-users] Raq Hacked
My Raq3 was hacked this weekend by 1i0n Crew.
24 hours later and $$$ to my colo provider. I'm
still recovering.
All index pages said Powered by H.U.C. ---the 1iOn Crew.
It was a mess.
I have just a small business and why did they pick
me? Well, I'm not gonna waste my time thinking about
this.
I figure I just want as many Cobalt users to hear about
it, so they can make sure they have taken the right
precautions. I paid the price! Hopefully someone else
can benefit from my awful experience. USE THE PKG UPDATES!
USE PORT SENTRY! DISABLE TELNET!
Joe A.
_________________________________________________________________
Get your FREE download of MSN Explorer at http://explorer.msn.com
_______________________________________________
cobalt-users mailing list
cobalt-users@xxxxxxxxxxxxxxx
To Subscribe or Unsubscribe, please go to:
http://list.cobalt.com/mailman/listinfo/cobalt-users