avatar
j*o
1
New Redhat 7.0, never patched before. Today,
I found a new account with uid 0.
Here is the /var/log/messages. This looks like a overflow
bug.
I don't know which program has this bug. Can anyone
give a hint?
Thank you.
avatar
D*N
2
If it's the never-patched Redhat you're vulunerable to the so-called
Ramen worm.. Looks like the user from 212.179.162.109 has already got
access to your machine thro the security hole from LPRng or wu-ftpd
Go get the patch as soon as possible from http://www.redhat.com/support/errata/
A complete reinstall is the safest option for you now. Then patch up
the system (every one is recommended.. :( that's a lot I know) and
disallow incoming requesting using tcp wrappers for all but trusted
ips.

【在 j*****o 的大作中提到】
: New Redhat 7.0, never patched before. Today,
: I found a new account with uid 0.
: Here is the /var/log/messages. This looks like a overflow
: bug.
: I don't know which program has this bug. Can anyone
: give a hint?
: Thank you.

avatar
j*o
3
Yes, It looks like LPRng.
Thank you.

【在 D****N 的大作中提到】
: If it's the never-patched Redhat you're vulunerable to the so-called
: Ramen worm.. Looks like the user from 212.179.162.109 has already got
: access to your machine thro the security hole from LPRng or wu-ftpd
: Go get the patch as soon as possible from http://www.redhat.com/support/errata/
: A complete reinstall is the safest option for you now. Then patch up
: the system (every one is recommended.. :( that's a lot I know) and
: disallow incoming requesting using tcp wrappers for all but trusted
: ips.

相关阅读
logo
联系我们隐私协议©2024 redian.news
Redian新闻
Redian.news刊载任何文章,不代表同意其说法或描述,仅为提供更多信息,也不构成任何建议。文章信息的合法性及真实性由其作者负责,与Redian.news及其运营公司无关。欢迎投稿,如发现稿件侵权,或作者不愿在本网发表文章,请版权拥有者通知本网处理。