RH6.0 had a vulnerable wu-ftpd.  That is the most likely point of access.
I had it happen to me and there was no evidence as they had cleared the
logs.  I only became aware because of an upstream filter/router that was
logging accesses.

Howard.
______________________________________________________
LANNet Computing Associates <http://www.lannet.com.au>

On Mon, 22 May 2000, DaZZa wrote:

> On Mon, 22 May 2000 [EMAIL PROTECTED] wrote:
> 
> > I realise there are security issues with Redhat 6.0 and will be installing 6.2
> > soon. In the meantime, what is the most likely method someone could use to
> > inject new userids in the /etc/passwd and /etc/shadow files? There is no record
> > of access by telnet, ftp nor anything else.
> 
> How long is a piece of string?
> 
> In other words, how much have you secured your machine from the standard
> install? RH by default is pretty open - lots of services running which
> aren't really needed, not much tightening of other stuff.
> 
> There's no way of waving a magic wand and saying "This is how you were
> hacked".
> 
> DaZZa
> 
> --
> SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
> To unsubscribe send email to [EMAIL PROTECTED] with
> unsubscribe in the text
> 

--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to