Re: [webmin-l] Re: Webmin BruteForce + Command execution - By Di42lo <DiAblo_2@012.net.il>

From: Jamie Cameron (jcameron_at_webmin.com)
Date: 12/23/04

  • Next message: William Geoghegan: "Re: phpBB Worm"
    To: webadmin-list@lists.sourceforge.net
    Date: 23 Dec 2004 22:17:35 +1100
    
    

    On Thu, 2004-12-23 at 20:34, Martin Mewes wrote:
    > Hello,
    >
    > amit sides <DiAblo_2@012.net.il> wrote :
    > > #!/usr/bin/perl
    > > ##
    > > # Webmin BruteForce + Command execution - By Di42lo
    > > <DiAblo_2@012.net.il> #
    > > # usage
    > > # ./bruteforce.webmin.pl <host> <command>
    > [...]
    >
    > this is a message from the maintainer ...
    >
    > ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    > I haven't seen this one before - but it would be blocked by Webmin's
    > password timeouts feature. However, this feature (surprisingly!) isn't
    > enabled by default ...
    > ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    >
    > On behalf of the maintainer I appreciate every input to secure the
    > software to its extend. Future versions of Webmin (if needed Usermin
    > too) will have this feature enabled by default.
    >
    > With this we encourage everyone using Webmin to enable this feature to
    > avoid a possible break-in.
    >
    > Again, we would like to tell the OP of this that it would be really nice
    > to know first about such issues, so we are ablte to / can do a
    > (full-)disclosure on items.

    Fortunately, it is quite easy to configure Webmin to defend against this kind
    of brute-force password guessing attack. Just do the following :

     - Go to the Webmin Configuration module.

     - Click on the Authentication icon.

     - Select 'Enable password timeouts'.

     - Click on the 'Save' button at the bottom of the page.

    Future releases will enable this by default.

     - Jamie

       


  • Next message: William Geoghegan: "Re: phpBB Worm"

    Relevant Pages

    • Re: Webmin BruteForce + Command execution - By Di42lo <DiAblo_2@012.net.il>
      ... However, this feature isn't ... On behalf of the maintainer I appreciate every input to secure the ... Future versions of Webmin (if needed Usermin ...
      (Bugtraq)
    • Re: webmail in FC3
      ... On Thu, 2005-07-07 at 08:46, Kanwar Ranbir Sandhu wrote: ... There is also one included in the usermin part of webmin. ... feature is that it already uses pam for login/password checking so ...
      (Fedora)
    • Re: Order of globbing result in bash, bug or feature?
      ... > language sort order should affect '_' in any case. ... Ask the maintainer of that locale (in general you might ... consider LC_COLLATE a feature as well if you needed it). ...
      (comp.unix.shell)
    • Re: webmail in FC3
      ... > There is also one included in the usermin part of webmin. ... > feature is that it already uses pam for login/password checking so ... even if it's just for normal users. ... Kanwar Ranbir Sandhu ...
      (Fedora)
    • Re: vim auto brace matching?
      ... though only a few months ago its maintainer sent me email discussing his ... reluctance to adopt the feature. ...
      (comp.editors)