Re: smoothall vpn im

William Anderson <[email protected]> Tue, 23 Nov 2004 09:36:31 +0000
Newsgroups gmane.comp.security.firewalls.smoothwall.general
Message-ID <[email protected]>
Alistair Francis wrote:
> Oops!
> 
> I hope I'm not the only one who finds this a little ironic? ;)
> 
> One would be interested to know what kinda server they're running and what
> exploit was used to hack them in the first place. Just based on the posts it
> sounds kinda like the old mdac vulnerability on MS IIS. Having said that, I
> took it for granted that the smoothie boff's would be using Apache or some
> such. Like I said, it'd be great if Neuro, mpot or someone in the know,
> could post the findings on the list.

I've only just discovered it's happened after finding a flurry of mails in 
my mailbox (dudes, i don't work there anymore - try [email protected] 
in future, more eyeballs see those mails!) after getting to work.

apache seems shutdown, but I haven't logged into the server until I can get 
an all clear from the guys.  I don't know for sure what caused the breach, 
but I've got a very good idea.  Clearly though, the guys are on the 
motherf---er, and I'm sure there will be a status msg later on in the day.

And for me, it's back to work :)  God, I love Netapps.  Did I say "love"?  I 
meant "want to destroy" :>

-- 
_ __/|  William Anderson      | "There's something about records which is
\`O_o'  neuro at well dot com |  really satisfying."
=(_ _)= http://neuro.me.uk/   |     -- John Peel (1939 - 2004)
    U  - Thhbt! GPG 0xFA5F1100 |
_______________________________________________
gpl mailing list
[email protected]
http://lists.smoothwall.org/mailman/listinfo/gpl

SmoothWall Stash - Buy Our Stuff! http://cafepress.com/smoothwall