[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] where's the list; and, have I been hacked?



"Tom Ritchford" <tom@xxxxxxxxxx> wrote:
> I have another theory.  I know that Datapipe, my provider, has a backdoor
> to my machine that lets them change root's password because
> they did it when I was hacked. (How does that work, anyway?)

Have you asked them?  Personally, I wouldn't be comfortable with my colo
having root access, especially if that wasn't disclosed when I signed the
contract.  And if they do have root access and when asked didn't tell me how
I'd be extremely concerned.  It's possible they created their own root user
(with a different username) with uid 0 and gid 0 with root user privileges.
Or they could have setup shell access on a non-standard port.  In any case,
if asked they should tell you how/why.  The decision of how to proceed is
your call.

--
Steve Werby
President, Befriend Internet Services LLC
http://www.befriend.com/