RH6.0 had a vulnerable wu-ftpd. That is the most likely point of access.
I had it happen to me and there was no evidence as they had cleared the
logs. I only became aware because of an upstream filter/router that was
logging accesses.
Howard.
______________________________________________________
LANNet Computing Associates <http://www.lannet.com.au>
On Mon, 22 May 2000, DaZZa wrote:
> On Mon, 22 May 2000 [EMAIL PROTECTED] wrote:
>
> > I realise there are security issues with Redhat 6.0 and will be installing 6.2
> > soon. In the meantime, what is the most likely method someone could use to
> > inject new userids in the /etc/passwd and /etc/shadow files? There is no record
> > of access by telnet, ftp nor anything else.
>
> How long is a piece of string?
>
> In other words, how much have you secured your machine from the standard
> install? RH by default is pretty open - lots of services running which
> aren't really needed, not much tightening of other stuff.
>
> There's no way of waving a magic wand and saying "This is how you were
> hacked".
>
> DaZZa
>
> --
> SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
> To unsubscribe send email to [EMAIL PROTECTED] with
> unsubscribe in the text
>
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text