RE: smoothall vpn im
"Alistair Francis" <ali-QGBN+/qDeXgGFrCMPLEOK/d9D2ou9A/[email protected]> Tue, 23 Nov 2004 08:27:33 +0200
| Newsgroups | gmane.comp.security.firewalls.smoothwall.general |
|---|---|
| Message-ID | <[email protected]> |
Oops! I hope I'm not the only one who finds this a little ironic? ;) One would be interested to know what kinda server they're running and what exploit was used to hack them in the first place. Just based on the posts it sounds kinda like the old mdac vulnerability on MS IIS. Having said that, I took it for granted that the smoothie boff's would be using Apache or some such. Like I said, it'd be great if Neuro, mpot or someone in the know, could post the findings on the list. Cheers, Alistair Francis Systems Administrator Comm Express Services SA (PTY) LTD TEL: +27 (0)11 475-5567 FAX: +27 (0)11 475-6238 CELL: +27 (0)84 607-7325 The information contained in this electronic mail message is confidential to the Matragon group of companies and may enjoy legal privilege. The contents are intended solely for the addressee and access thereto by anyone else is unauthorised. Should you not be the intended recipient, kindly delete the message and inform us. Any disclosure, copying or distribution is prohibited and may be unlawful. Please also note that any action taken, or omitted to be taken in reliance on the information contained herein is done at your own risk. -----Original Message----- From: [email protected] [mailto:[email protected]]On Behalf Of Samuel Gordon-Stewart Sent: 23 November 2004 07:01 To: [email protected] Subject: Re: [gpl] smoothall vpn im On Tue, 23 Nov 2004 14:45:03 +1100, Samuel Gordon-Stewart <[email protected]> wrote: > Yes, the smoothwall website has been hacked Hmmmm, I am quoting myself...proof that I am insane!!! This just goes to show why you should setup publicly accessible servers in the orange zone, atm we have no way of knowing what kind of access the attacker has to the SW webserver and as such, what kind of access they may have to other computers on the same network (if any) Imagine if this was your webserver and you had it on green, how long would it be until the attacker finds the other computers on your network... The other cause for concern is that the attacker might have access to the personal information stored by the forums, such as full names, email addresses (even the ones hidden from the public), IP addresses you have had when visiting the forums etc. My other concern is how much of this can be blamed on memset (the people who host the server), I suppose we won't know that until we know what happened to the server in the first place. Now that I have finished my little rant (thankyou for reading it), I will quote myself again: "I am not a member of the smoothwall team, nor do I work for SmoothWall Ltd. My words should not be read as official responses as they are not, they are my words, and I take full responsibility for them." samuel -- I Must be really old in dog years!! Afternoons With Samuel http://tinyurl.com/5fl3e Listen to my lovely music www.thefunkyasylum.com/notnice.mp3 Protect your network www.smoothwall.org _______________________________________________ gpl mailing list [email protected] http://lists.smoothwall.org/mailman/listinfo/gpl SmoothWall Stash - Buy Our Stuff! http://cafepress.com/smoothwall _______________________________________________ gpl mailing list [email protected] http://lists.smoothwall.org/mailman/listinfo/gpl SmoothWall Stash - Buy Our Stuff! http://cafepress.com/smoothwall