dtspcd compromises

From: Russell Fulton (R.FULTON@auckland.ac.nz)
Date: 01/21/02


From: Russell Fulton <R.FULTON@auckland.ac.nz>
To: incidents@securityfocus.com
Date: 21 Jan 2002 20:26:34 +1300

Just an FYI:

Early this morning (0220 local time, Monday) we had a couple of SUN
machines compromised via dtspcd. The exploit started a second copy of
inetd with a configuration file /tmp/x which bound a root shell on 1524
(ingresslock).

Later in the morning (0800) one of the machines started a synflood
attack on another machine on our network. This combined with the fact
that the attack originated from a local ISP strongly suggests this is
the work of some of our students, sigh...

No root kit was installed and no other back doors found, we are
reinstalling anyway, of course...

The snort rules in the experimental rules file picked up the attack.

-- 
Russell Fulton, Computer and Network Security Officer
The University of Auckland,  New Zealand

---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: Thought on disconnecting hacked computers
    ... > Looking at my firewall logs, it seems evident that there are many ... > attempts per hour to exploit vulnerabilities that are blocked by the ... > immediately blocked all traffic from the affected machines, ... The problem is the likelihood for one man's attack signature match ...
    (comp.security.misc)
  • Re: Setting The System Clock [Linux]
    ... The machines ... >>which were powered on did deal with the time change. ... > clock set to local time is to cope with Windows's broken time handling. ... If that's the price I pay for keeping hardware clocks in local ...
    (comp.os.linux.misc)
  • Re: Setting The System Clock [Linux]
    ... The machines ... >>which were powered on did deal with the time change. ... > clock set to local time is to cope with Windows's broken time handling. ... If that's the price I pay for keeping hardware clocks in local ...
    (comp.unix.questions)
  • Re: Question regarding attack
    ... I recently experienced the exact same logon behavior after logging off and ... to log on again as administrator. ... > A couple of our Windows 2000/NT machines were attacked overnight recently. ... difficulty tracking down how the attack was executed. ...
    (Focus-Microsoft)
  • Re: Updated list of most popular pins
    ... the percentage of those machines owned by RGP folks. ... 48 WHITEWATER ... 45 ATTACK FROM MARS ...
    (rec.games.pinball)