[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [cobalt-users] where's the list; and, have I been hacked?
- Subject: Re: [cobalt-users] where's the list; and, have I been hacked?
- From: "Steve Werby" <steve-lists@xxxxxxxxxxxx>
- Date: Sun Jun 10 08:16:03 2001
- List-id: Mailing list for users to share thoughts on Cobalt products. <cobalt-users.list.cobalt.com>
"Tom Ritchford" <tom@xxxxxxxxxx> wrote:
> I have another theory. I know that Datapipe, my provider, has a backdoor
> to my machine that lets them change root's password because
> they did it when I was hacked. (How does that work, anyway?)
Have you asked them? Personally, I wouldn't be comfortable with my colo
having root access, especially if that wasn't disclosed when I signed the
contract. And if they do have root access and when asked didn't tell me how
I'd be extremely concerned. It's possible they created their own root user
(with a different username) with uid 0 and gid 0 with root user privileges.
Or they could have setup shell access on a non-standard port. In any case,
if asked they should tell you how/why. The decision of how to proceed is
your call.
--
Steve Werby
President, Befriend Internet Services LLC
http://www.befriend.com/