Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 6 Feb 2002 14:05:30 +0300 (MSK)
From:      "Artem 'Zazoobr' Ignatjev" <timon@memphis.mephi.ru>
To:        brett@lariat.org, freebsd-security@FreeBSD.ORG, victor@customdynamic.net
Subject:   Re: Is this evidence of a break-in attempt?
Message-ID:  <200202061105.g16B5Uo33060@memphis.mephi.ru>
In-Reply-To: <4.3.2.7.2.20020205125336.02758450@localhost>

next in thread | previous in thread | raw e-mail | index | archive | help
> From owner-freebsd-security@FreeBSD.ORG Tue Feb  5 22:59:39 2002
> Date: Tue, 05 Feb 2002 12:54:41 -0700
> To: Victor Grey <victor@customdynamic.net>, <freebsd-security@FreeBSD.ORG>
> From: Brett Glass <brett@lariat.org>
> Subject: Re: Is this evidence of a break-in attempt?
>
> In a word, yes. Looks like they went to the box with a
> keyboard and a mouse, rebooted, and tried to log in.
> Clearly, they were so clueless that they did not know
> about single-user mode.
>
Well, if console is marked as `insecure' (which is MY default policy) 
single mode couldn't help them too much. 
But there is a way to get contents of any file in root filesystem from
loader(8), so they could get root hash.

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200202061105.g16B5Uo33060>