Re: [pgsql-www] FW: (AUSCERT ESB-2003.0563) CERT Advisory CA-2003-21 - Mailing list pgsql-advocacy

From Neil Conway
Subject Re: [pgsql-www] FW: (AUSCERT ESB-2003.0563) CERT Advisory CA-2003-21
Date
Msg-id 20030814061839.GJ76772@home.samurai.com
Whole thread Raw
In response to Re: [pgsql-www] FW: (AUSCERT ESB-2003.0563) CERT Advisory CA-2003-21  (Justin Clift <justin@postgresql.org>)
List pgsql-advocacy
On Thu, Aug 14, 2003 at 02:09:32PM +0800, Justin Clift wrote:
> Wu-FTPd has probably the worst track record on the planet for FTP
> vulnerabilities.

Actually, the cracker didn't even use an ftpd security hole,
apparently:

-----
A root compromise and a Trojan horse were discovered on gnuftp.gnu.org,
the FTP server of the GNU project.  The machine appears to have been
cracked in March 2003, but we only discovered the crack in the last week
of July 2003.  The modus operandi of the cracker shows that (s)he was
interested primarily in using gnuftp to collect passwords and as a
launching point to attack other machines.  It appears that the machine was
cracked using a ptrace exploit by a local user immediately after the
exploit was posted.

(For the ptrace bug, a root-shell exploit was available on 17 March 2003,
 and a working fix was not available on linux-kernel until the following
 week.  Evidence found on the machine indicates that gnuftp was cracked
 during that week.)
-----

Besides, this is OT for this list anyway.

-Neil


pgsql-advocacy by date:

Previous
From: Justin Clift
Date:
Subject: Re: [pgsql-www] FW: (AUSCERT ESB-2003.0563) CERT Advisory CA-2003-21
Next
From: Chris Phelan
Date:
Subject: Re: Draft #6: Semi-Final