l i n u x - u s e r s - g r o u p - o f - d a v i s
Next Meeting:
July 7: Social gathering
Next Installfest:
Latest News:
Jun. 14: June LUGOD meeting cancelled
Page last updated:
2004 May 01 10:29

The following is an archive of a post made to our 'vox-tech mailing list' by one of its subscribers.

Report this post as spam:

(Enter your email address)
Re: [vox-tech] Password Security...
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [vox-tech] Password Security...

Hash: SHA1

On Saturday 01 May 2004 09:34 am, William Perdue wrote:
> I've been having some trouble with my security in my server.... I am
> running Red Hat Linux 9 with the Linux SSH Client software.

Have you been keeping up with bug fixes and updates?  Do you have users on 
your system?  What services do you run?

> Looking through my logs, I found that a hacker got hold of my Root
> password... it was _not_ the default (it was 17 characters) .... the server
> sits behind my router with a local IP address

How do you know?  What and where was the proof?

> My Firewall is set at a high level  and The Server config is far from the
> defaults...
> My Question: could they have obtained my root password?..
> Another thing,,, Is there an easy way I can figure out if they installed
> any software on my server, like a trapdoor that would allow access now that
> I have changed the password?

If they got the root password then the machine and the data it contains cannot 
be trusted.  Time to rebuild fresh.

- -- 
Mark Street, RHCE
- --
Key fingerprint = 3949 39E4 6317 7C3C 023E  2B1F 6FB3 06E7 D109 56C0
GPG key http://www.oswizards.com/pubkey.asc
Version: GnuPG v1.2.3 (GNU/Linux)

vox-tech mailing list

LUGOD Group on LinkedIn
Sign up for LUGOD event announcements
Your email address:
LUGOD Group on Facebook
'Like' LUGOD on Facebook:

Hosting provided by:
Sunset Systems
Sunset Systems offers preconfigured Linux systems, remote system administration and custom software development.

LUGOD: Linux Users' Group of Davis
PO Box 2082, Davis, CA 95617
Contact Us

LUGOD is a 501(c)7 non-profit organization
based in Davis, California
and serving the Sacramento area.
"Linux" is a trademark of Linus Torvalds.

Sponsored in part by:
Appahost Applications
For a significant contribution towards our projector, and a generous donation to allow us to continue meeting at the Davis Library.