Re: SGI/O2 trouble----May affect you too!

T. Pratum (pratum@u.washington.edu)
Mon, 6 Dec 1999 14:23:39 -0800 (PST)

Xifeng-
You have been hacked by the "/tmp/bob" attack (using autofs security
hole). If you search the ammrl archives you will see many others who have
also suffered this, including myself. You need to turn off autofs
immediately, reboot and see if anything else was compromised.


Tom Pratum
Dept of Chemistry
Box 351700
Univ of Washington
Seattle, WA 98195
206-685-2581
pratum@u.washington.edu
http://staff.washington.edu/pratum

On Mon, 6 Dec 1999, Xinfeng Gao wrote:

> Dear Bruker Users,
>
> We have two SGI/O2 operating pm Irix 6.3. On Nov 30 at exactly the same
> time (18:02) they both have the "su" password protection turned off. So
> anyone can get to super user mode without a root password. we found out
> that a file called .rhost containing two + signs was added under /. After
> deleting the file "su" works normal (will ask password) again. This may
> affect anyone who has a O2 if the problem is caused by some system bug. We
> know another O2 in our campus having the same problem starting at the same
> time.
>
> Another problem may be related to the first one: the SYSLOG file is now
> constantly adding this line
> "bootp [16713]: DHCP request, server not configured. exiting."
>
> Have anyone got this problem also? If you have how have you solved it?
>
> Thanks,
>
> Wei
>
>
>