[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Turley loses some more brain cells



> OK... I'll take your word for it.  And download lightly so as not to attract your 
> interest.  ;)  Thanks for reminding folks that they leave tracks though.  Perhaps 
> they'll think twice.  ;)

I don't care about the ftp downloads; those are irrelevant to me. The only
reason they're logged is for analysis of suspected intrustion attempts.

> Well...  You didn't detect MY traceroute.  ;)

If you're running a traceroute that I'm not detecting, my hat is off to
you... however, I sincerely doubt that.

> Or other folks who are curious about any URL posted with only an IP#.  Assuming 
> that was me might be pretty good odds, but then how many more traceroutes have 
> hit you?  One more at least in the last 6 hours at least.  That was me.  ;)

Ya know, in the last month... 2 total. Including one you claim to have run
from wetelephant.cotse.com... which I *doubt* is your home box, since it's
running Solaris 2.6 or 2.7.... and btw, take off sendmail and put on
qmail. Sendmail is a security hole waiting to happen. ;-)

Traceroutes just aren't a common thing these days. Portscans and Syn
floods, they happen all the time. But traceroutes? Why the heck would you
want to traceroute? It doesn't serve much purpose for cracking a box.

> Oh, I know this.  And some folks keep those logs for a time and then discard 
> them.  Or keep them for life.  Whoopee!  ;)

Mine are dealt with in a secure manner.

> Well.... _An_ IP is there now.  Happy hunting.  ;)

So does cotse hand out shell accounts to everyone, or are you actually
responsible for admin'ing that box? If admin'ing, you should lock it down
a little better. I haven't done a full audit on it, but a cursory glance
reveals a half-hearted attempt at security.

~Warren