From owner-freebsd-questions Tue Jul 31 2: 2:14 2001 Delivered-To: freebsd-questions@freebsd.org Received: from obsecurity.dyndns.org (adsl-63-207-60-69.dsl.lsan03.pacbell.net [63.207.60.69]) by hub.freebsd.org (Postfix) with ESMTP id 0C18237B405 for ; Tue, 31 Jul 2001 02:02:10 -0700 (PDT) (envelope-from kris@obsecurity.org) Received: by obsecurity.dyndns.org (Postfix, from userid 1000) id 28CE166B39; Tue, 31 Jul 2001 02:02:09 -0700 (PDT) Date: Tue, 31 Jul 2001 02:02:08 -0700 From: Kris Kennaway To: Sys Admin Cc: freebsd-questions@FreeBSD.ORG Subject: Re: ssh to a compromised (probably) box Message-ID: <20010731020208.A18704@xor.obsecurity.org> References: Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-md5; protocol="application/pgp-signature"; boundary="4Ckj6UjgE2iN1+kY" Content-Disposition: inline User-Agent: Mutt/1.2.5i In-Reply-To: ; from admin@cb21.co.jp on Tue, Jul 31, 2001 at 05:17:16PM +0900 Sender: owner-freebsd-questions@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.ORG --4Ckj6UjgE2iN1+kY Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Tue, Jul 31, 2001 at 05:17:16PM +0900, Sys Admin wrote: >=20 > Hello, >=20 > Just being curious. >=20 > Considering the following scenario >=20 > Box A (local) ----------------------> Box B (remote) >=20 > Assume that box B has been compromised (root powers) >=20 > If I ssh into box B from A, su to root and start investigating the > damage done, will the hacker be able to sniff the root password ? (during > su to root) >=20 > [ Given that critical binaries (sshd, su ..) remained unchanged ] Yes. They can do anything on that box now. Kris --4Ckj6UjgE2iN1+kY Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (FreeBSD) Comment: For info see http://www.gnupg.org iD8DBQE7ZnQPWry0BWjoQKURAoNaAKC3TEhV4B4PFlSc/L1txCHYlO7AlgCgtomh pO+Lw9AnKt82Iplkk5PKT88= =ih0N -----END PGP SIGNATURE----- --4Ckj6UjgE2iN1+kY-- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-questions" in the body of the message