List /home directory without logging in?

From: Alan Baker (alanwbaker_at_yahoo.com)
Date: 07/05/04

  • Next message: Bit Twister: "Re: List /home directory without logging in?"
    Date: 4 Jul 2004 23:19:28 -0700
    
    

    Someone recently tried to log into all the userids on my Linux box.
    First they connected several times via http, telnet, ftp, pop3, and
    imap but were unsuccessful in logging in. Then they tried every
    userid twice in alphabetical order via SSH. Also unsuccessfully.
    (Use those strong passwords, friends!)

    They didn't actually use the names in /etc/passwd, but instead tried
    all directory names under /home (including non-users like lost+found).
     This makes me wonder if the preliminary probes revealed /home's
    directory list.

    How could someone list /home without logging in? Is there a known
    vuln I'm missing?

      Alan


  • Next message: Bit Twister: "Re: List /home directory without logging in?"

    Relevant Pages

    • List /home directory without logging in?
      ... Someone recently tried to log into all the userids on my Linux box. ... imap but were unsuccessful in logging in. ... How could someone list /home without logging in? ...
      (comp.os.linux.security)
    • Re: List /home directory without logging in?
      ... > Someone recently tried to log into all the userids on my Linux box. ... > First they connected several times via http, telnet, ftp, pop3, and ... > imap but were unsuccessful in logging in. ...
      (comp.os.linux.security)
    • Re: List /home directory without logging in?
      ... > Someone recently tried to log into all the userids on my Linux box. ... > First they connected several times via http, telnet, ftp, pop3, and ... > imap but were unsuccessful in logging in. ...
      (comp.security.unix)
    • RE: Cannot type or select in an IE 6.0 window
      ... DITTO@! ... > I am unable to type anything in a window within IE 6. ... Unable to enter userids ... > for logging on to web pages or enter passwords or even respond to message ...
      (microsoft.public.windows.inetexplorer.ie6.browser)
    • Re: List /home directory without logging in?
      ... > Someone recently tried to log into all the userids on my Linux box. ... > First they connected several times via http, telnet, ftp, pop3, and ... > imap but were unsuccessful in logging in. ... If you had your firewall on and blocked inbound conections, ...
      (comp.os.linux.security)