Howard Lowndes wrote:
> 
> I spent a very unpleasant morning cleaning up a site after it got
> breached.
> 
> The exploit occurred at 7:13 because access to the breached site was via a
> firewall that deliberately logs TCP SYN packets.  The attacked site was
> running in.ftpd version wu-2.5.0(1) 

<snip>

> I have not heard of any vulnerabilities in late version ftpd proggies, but
> it seems that there is one.

Yep, I vulnerability in wu-ftpd version 2.5 was published in October
last year. Redhat released an upgrade (wu-ftpd-2.6.0) a couple of days
later. Every script kiddie on the planet must know how to crack the old
one. 

This shows how important it is to keep up-to-date with these reports.
The way I do it by reading the security page of Linux Weekly News:

     http://lwn.net

> If anyone wants further info then please contact me off list, similarly if
> any one can offer constructive comment.  Needless to say I have very
> copious notes of everything I discovered.

As someone suggested, contact AUSCERT.

Erik
-- 
+-------------------------------------------------+
     Erik de Castro Lopo     [EMAIL PROTECTED]
+-------------------------------------------------+
Percussive Maintenance: The fine art of whacking the c**p out 
of an electronic device to get it to work again.
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to