Howard Lowndes wrote:
>
> I spent a very unpleasant morning cleaning up a site after it got
> breached.
>
> The exploit occurred at 7:13 because access to the breached site was via a
> firewall that deliberately logs TCP SYN packets. The attacked site was
> running in.ftpd version wu-2.5.0(1)
<snip>
> I have not heard of any vulnerabilities in late version ftpd proggies, but
> it seems that there is one.
Yep, I vulnerability in wu-ftpd version 2.5 was published in October
last year. Redhat released an upgrade (wu-ftpd-2.6.0) a couple of days
later. Every script kiddie on the planet must know how to crack the old
one.
This shows how important it is to keep up-to-date with these reports.
The way I do it by reading the security page of Linux Weekly News:
http://lwn.net
> If anyone wants further info then please contact me off list, similarly if
> any one can offer constructive comment. Needless to say I have very
> copious notes of everything I discovered.
As someone suggested, contact AUSCERT.
Erik
--
+-------------------------------------------------+
Erik de Castro Lopo [EMAIL PROTECTED]
+-------------------------------------------------+
Percussive Maintenance: The fine art of whacking the c**p out
of an electronic device to get it to work again.
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text