[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Turley loses some more brain cells
> OK... I'll take your word for it. And download lightly so as not to attract your
> interest. ;) Thanks for reminding folks that they leave tracks though. Perhaps
> they'll think twice. ;)
I don't care about the ftp downloads; those are irrelevant to me. The only
reason they're logged is for analysis of suspected intrustion attempts.
> Well... You didn't detect MY traceroute. ;)
If you're running a traceroute that I'm not detecting, my hat is off to
you... however, I sincerely doubt that.
> Or other folks who are curious about any URL posted with only an IP#. Assuming
> that was me might be pretty good odds, but then how many more traceroutes have
> hit you? One more at least in the last 6 hours at least. That was me. ;)
Ya know, in the last month... 2 total. Including one you claim to have run
from wetelephant.cotse.com... which I *doubt* is your home box, since it's
running Solaris 2.6 or 2.7.... and btw, take off sendmail and put on
qmail. Sendmail is a security hole waiting to happen. ;-)
Traceroutes just aren't a common thing these days. Portscans and Syn
floods, they happen all the time. But traceroutes? Why the heck would you
want to traceroute? It doesn't serve much purpose for cracking a box.
> Oh, I know this. And some folks keep those logs for a time and then discard
> them. Or keep them for life. Whoopee! ;)
Mine are dealt with in a secure manner.
> Well.... _An_ IP is there now. Happy hunting. ;)
So does cotse hand out shell accounts to everyone, or are you actually
responsible for admin'ing that box? If admin'ing, you should lock it down
a little better. I haven't done a full audit on it, but a cursory glance
reveals a half-hearted attempt at security.
~Warren