Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 2 Jul 1996 21:34:27 -0400 (EDT)
From:      "Pedro F. Giffuni S." <pgiffuni@biblioteca.campus.unal.edu.co>
To:        security@freebsd.org
Subject:   Sendmail cracked!
Message-ID:  <Pine.A32.3.91.960702212427.13507A-100000@biblioteca.campus.unal.edu.co>

next in thread | raw e-mail | index | archive | help
Hello:
I am running kerberos and DES, but to my surprise my 2 FreeBSD's and my 
AIX's received me with a funny message: /etc/motd was modified and wtmp 
erased.
I knew I was under attack before because of some failed logins, on my fbsds, 
and strange "cannot execute" messages un my AIXs root mail. By the message I 
received, I know other computers in the campus are cracked also.

My solution was securing sendmail by running it in the inetd.conf with 
tcp_wrappers. It is a last moment solution...Is there a new sendmail, a 
patch, or a configuration option?

regards,
Pedro.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.A32.3.91.960702212427.13507A-100000>