RE: smoothall vpn im

"Alistair Francis" <ali-QGBN+/qDeXgGFrCMPLEOK/d9D2ou9A/[email protected]> Tue, 23 Nov 2004 08:27:33 +0200
Newsgroups gmane.comp.security.firewalls.smoothwall.general
Message-ID <[email protected]>
Oops!

I hope I'm not the only one who finds this a little ironic? ;)

One would be interested to know what kinda server they're running and what
exploit was used to hack them in the first place. Just based on the posts it
sounds kinda like the old mdac vulnerability on MS IIS. Having said that, I
took it for granted that the smoothie boff's would be using Apache or some
such. Like I said, it'd be great if Neuro, mpot or someone in the know,
could post the findings on the list.

Cheers,

Alistair Francis
Systems Administrator
Comm Express Services SA (PTY) LTD
TEL:    +27 (0)11 475-5567
FAX:   +27 (0)11 475-6238
CELL: +27 (0)84 607-7325

The information contained in this electronic mail message is confidential to
the Matragon group of companies and may enjoy legal privilege. The contents
are intended solely for the addressee and access thereto by anyone else is
unauthorised. Should you not be the intended recipient, kindly delete the
message and inform us. Any disclosure, copying or distribution is prohibited
and may be unlawful. Please also note that any action taken, or omitted to
be taken in reliance on the information contained herein is done at your own
risk.



-----Original Message-----
From: [email protected]
[mailto:[email protected]]On Behalf Of Samuel
Gordon-Stewart
Sent: 23 November 2004 07:01
To: [email protected]
Subject: Re: [gpl] smoothall vpn im


On Tue, 23 Nov 2004 14:45:03 +1100, Samuel Gordon-Stewart
<[email protected]> wrote:
> Yes, the smoothwall website has been hacked

Hmmmm, I am quoting myself...proof that I am insane!!!
This just goes to show why you should setup publicly accessible
servers in the orange zone, atm we have no way of knowing what kind of
access the attacker has to the SW webserver and as such, what kind of
access they may have to other computers on the same network (if any)

Imagine if this was your webserver and you had it on green, how long
would it be until the attacker finds the other computers on your
network...

The other cause for concern is that the attacker might have access to
the personal information stored by the forums, such as full names,
email addresses (even the ones hidden from the public), IP addresses
you have had when visiting the forums etc.

My other concern is how much of this can be blamed on memset (the
people who host the server), I suppose we won't know that until we
know what happened to the server in the first place.

Now that I have finished my little rant (thankyou for reading it), I
will quote myself again:
"I am not a member of the smoothwall team, nor do I work for
SmoothWall Ltd. My words should not be read as official responses as
they are not, they are my words, and I take full responsibility for
them."

samuel
--
I Must be really old in dog years!!
Afternoons With Samuel http://tinyurl.com/5fl3e
Listen to my lovely music www.thefunkyasylum.com/notnice.mp3
Protect your network www.smoothwall.org
_______________________________________________
gpl mailing list
[email protected]
http://lists.smoothwall.org/mailman/listinfo/gpl

SmoothWall Stash - Buy Our Stuff! http://cafepress.com/smoothwall
_______________________________________________
gpl mailing list
[email protected]
http://lists.smoothwall.org/mailman/listinfo/gpl

SmoothWall Stash - Buy Our Stuff! http://cafepress.com/smoothwall