Re: [pgsql-www] FW: (AUSCERT ESB-2003.0563) CERT Advisory CA-2003-21

From: Neil Conway <neilc(at)samurai(dot)com>
To: Justin Clift <justin(at)postgresql(dot)org>
Cc: The Hermit Hacker <scrappy(at)postgresql(dot)org>, pgsql-www(at)postgresql(dot)org, PostgreSQL Advocacy and Marketing Mailing List <pgsql-advocacy(at)postgresql(dot)org>
Subject: Re: [pgsql-www] FW: (AUSCERT ESB-2003.0563) CERT Advisory CA-2003-21
Date: 2003-08-14 06:18:39
Message-ID: 20030814061839.GJ76772@home.samurai.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-advocacy

On Thu, Aug 14, 2003 at 02:09:32PM +0800, Justin Clift wrote:
> Wu-FTPd has probably the worst track record on the planet for FTP
> vulnerabilities.

Actually, the cracker didn't even use an ftpd security hole,
apparently:

-----
A root compromise and a Trojan horse were discovered on gnuftp.gnu.org,
the FTP server of the GNU project. The machine appears to have been
cracked in March 2003, but we only discovered the crack in the last week
of July 2003. The modus operandi of the cracker shows that (s)he was
interested primarily in using gnuftp to collect passwords and as a
launching point to attack other machines. It appears that the machine was
cracked using a ptrace exploit by a local user immediately after the
exploit was posted.

(For the ptrace bug, a root-shell exploit was available on 17 March 2003,
and a working fix was not available on linux-kernel until the following
week. Evidence found on the machine indicates that gnuftp was cracked
during that week.)
-----

Besides, this is OT for this list anyway.

-Neil

In response to

Browse pgsql-advocacy by date

  From Date Subject
Next Message Chris Phelan 2003-08-14 06:28:04 Re: Draft #6: Semi-Final
Previous Message Justin Clift 2003-08-14 06:09:32 Re: [pgsql-www] FW: (AUSCERT ESB-2003.0563) CERT Advisory CA-2003-21