Re: List /home directory without logging in?

From: Bit Twister (BitTwister_at_localhost.localdomain)
Date: 07/05/04


Date: Mon, 05 Jul 2004 06:37:06 GMT

On 4 Jul 2004 23:19:28 -0700, Alan Baker wrote:
> Someone recently tried to log into all the userids on my Linux box.
> First they connected several times via http, telnet, ftp, pop3, and
> imap but were unsuccessful in logging in. Then they tried every
> userid twice in alphabetical order via SSH. Also unsuccessfully.
> (Use those strong passwords, friends!)

Sounds like /home was visable. Does indicates something has a hole.
If you had your firewall on and blocked inbound conections, they
should not have gotten to the inforamtion.

Since you indicated they connected several times to several services
that would tell me you have no firewall. That would be a basic vuln
you are missing. Can we assume you have been to your vendor's site and
have kept up to date with all fixes/updates.



Relevant Pages

  • Re: List /home directory without logging in?
    ... > Someone recently tried to log into all the userids on my Linux box. ... > First they connected several times via http, telnet, ftp, pop3, and ... > imap but were unsuccessful in logging in. ... If you had your firewall on and blocked inbound conections, ...
    (comp.os.linux.security)
  • Re: List /home directory without logging in?
    ... > Someone recently tried to log into all the userids on my Linux box. ... > First they connected several times via http, telnet, ftp, pop3, and ... > imap but were unsuccessful in logging in. ...
    (comp.os.linux.security)
  • Re: List /home directory without logging in?
    ... > Someone recently tried to log into all the userids on my Linux box. ... > First they connected several times via http, telnet, ftp, pop3, and ... > imap but were unsuccessful in logging in. ...
    (comp.security.unix)
  • List /home directory without logging in?
    ... Someone recently tried to log into all the userids on my Linux box. ... imap but were unsuccessful in logging in. ... How could someone list /home without logging in? ...
    (comp.security.unix)
  • List /home directory without logging in?
    ... Someone recently tried to log into all the userids on my Linux box. ... imap but were unsuccessful in logging in. ... How could someone list /home without logging in? ...
    (comp.os.linux.security)