Re: 12.177.9.5

Alexey Lobanov <[email protected]>
Newsgroups gmane.mail.spam.dsbl.admin
Message-ID <[email protected]>
Hello.

On 14/09/05 17:14, David Cornett wrote:

> The accounts you have mentioned were unfortunately created for test purposes
> by us.

To my experience, "backup" with administrative rights and default
password "backup" is autocreated by some [brain-damaged] backup software
for MS-Windows. Tou are not the first victim.  The real question is how
long ago was it done? Have anyone used this account through remote
desktop, web access or so on, to set up control over your host? I would
assume that it was done if this account existed more than a week or so.

>  We have, as of yesterday, gone through our entire user list.  If you
> would, go ahead and run the test for me one more time.  We are also going to
> the extent of sending out a mandatory password change to all of our users.

Please note that both compromised accouns were not related to any real
users.

Anyway, the standard test is over, and nothing more was found.

Best,
Alexey


> And there will be some password rules applied to them.
> 
> -----Original Message-----
> From: Alexey Lobanov [mailto:[email protected]] 
> Sent: Tuesday, September 13, 2005 8:44 AM
> To: David Cornett
> Cc: [email protected]
> Subject: Re: [DSBL-Contact] 12.177.9.5
> 
> Hello.
> 
> On 09/13/2005 05:33 PM, David Cornett wrote:
> 
> 
>>Is there any testing process that we can request before we try your
> 
> removal
> 
>>process.
> 
> 
> This maillist is a right place for this request. The standard test based
> on real spammer activity is in progress now.
> 
> ...Oops. It had an effect:
> 
> Server accepted message
> AUTH=cram-md5 USER=backup PASS=backup IP=12.177.9.5
> 
> The situation is much more serious than an open relay. In difference
> from "test", "backup" is an administrative account. It is VERY POSSIBLE
> that whole system has been compromised and backdoored already through
> this account. The practical recommendation is simple: disconnect,
> reinstall from scratch, set new passwords for all accounts, apply
> security audits. Sorry.
> 
> 
>> We have gotten rid of our open relay and also the test / test
>>account.
> 
> 
> I believe, a proper action could be to use any automated tool for
> internal password auditing. There is a plenty of security tools being
> able to detect accounts with weak passwords. Any external test will not
> be so effective and can miss something important.
> 
> best,
> Alexey
> DSBL volunteer
> 
> 
> 
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.