Re: How could this account have been cracked?



"robb@xxxxxxx" typed:
Nathanael Hoyle wrote:
So the account's existence was probably not revealed by the login
(if there were already a keylogger on the system, you were flat
screwed from the start).

Yes, and this may be the case.

So, although that logically, there's no real true defense, I've done
a few things (added deny all sshd, removed software I'm not
using...) and hopefully the system will hold for a week or two until
I have the money and time to rebuild the server.

If the compromised machine in question is *acm.org*, then I *know* how
it got compromised. Do drop me a note, if you wish to know. :-)

And if *acm.org* ain't the compromised machine, then, well, oops. ;-)

--
Ayaz Ahmed Khan

Then, gently touching my face, she hesitated for a moment as her
incredible eyes poured forth into mine love, joy, pain, tragedy,
acceptance, and peace. "'Bye for now," she said warmly.
-- Thea Alexander, "2150 A.D."

.



Relevant Pages

  • Re: How could this account have been cracked?
    ... Nathanael Hoyle wrote: ... there were already a keylogger on the system, ... and time to rebuild the server. ...
    (comp.os.linux.security)
  • Explorer wont launch
    ... I'll have to bite the bullet and rebuild the system. ... the Open Office files I created are compatible w/ MS- ... >the browser flat quit launching. ... >I uninstalled and reinstalled explorer from cd. ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: Bulk inserts into SQL Server 2000 from Flat Files
    ... I'm writing a Window's Service in VB.NET to take information from flat ... and then subsequently into the database. ... Either upgrade to ADO.NET 2.0 / SQL Server 2005 and use SQLBulkCopy ...
    (microsoft.public.dotnet.framework.adonet)
  • Re: about RIS
    ... You need a flat CD-ROM image on the server that matches the OS you are ... trying to RIPREP from the workstation. ... If you are trying to Riprep a WinXP RTM ...
    (microsoft.public.win2000.setup_deployment)
  • Advice on parsing flat test files for certain strings
    ... I manage about 100 servers and each server produces a flat text file ... I can import this flat text file into a table. ... I could also produce another table containing text strings and an ID field ... Logs) and would like to use an input trigger here. ...
    (microsoft.public.sqlserver.programming)