RE: 12.177.9.5
"David Cornett" <[email protected]>
| Newsgroups | gmane.mail.spam.dsbl.admin |
|---|---|
| Message-ID | <200509140916620.SM01616@david0105> |
Unfortunately backup is created with backup exec. Fortunately the only ports we have open are actually allowed are imail and icmp. Remote access port 3389 is not open. So we should be ok. Fortunately most of the mail accounts on that server will be moved off due to a change in our organization's name. Which allowed us to purchase a new server to use for mail. David Cornett -----Original Message----- From: Alexey Lobanov [mailto:[email protected]] Sent: Wednesday, September 14, 2005 9:05 AM To: David Cornett Cc: [email protected] Subject: Re: [DSBL-Contact] 12.177.9.5 Hello. On 14/09/05 17:14, David Cornett wrote: > The accounts you have mentioned were unfortunately created for test purposes > by us. To my experience, "backup" with administrative rights and default password "backup" is autocreated by some [brain-damaged] backup software for MS-Windows. Tou are not the first victim. The real question is how long ago was it done? Have anyone used this account through remote desktop, web access or so on, to set up control over your host? I would assume that it was done if this account existed more than a week or so. > We have, as of yesterday, gone through our entire user list. If you > would, go ahead and run the test for me one more time. We are also going to > the extent of sending out a mandatory password change to all of our users. Please note that both compromised accouns were not related to any real users. Anyway, the standard test is over, and nothing more was found. Best, Alexey > And there will be some password rules applied to them. > > -----Original Message----- > From: Alexey Lobanov [mailto:[email protected]] > Sent: Tuesday, September 13, 2005 8:44 AM > To: David Cornett > Cc: [email protected] > Subject: Re: [DSBL-Contact] 12.177.9.5 > > Hello. > > On 09/13/2005 05:33 PM, David Cornett wrote: > > >>Is there any testing process that we can request before we try your > > removal > >>process. > > > This maillist is a right place for this request. The standard test based > on real spammer activity is in progress now. > > ...Oops. It had an effect: > > Server accepted message > AUTH=cram-md5 USER=backup PASS=backup IP=12.177.9.5 > > The situation is much more serious than an open relay. In difference > from "test", "backup" is an administrative account. It is VERY POSSIBLE > that whole system has been compromised and backdoored already through > this account. The practical recommendation is simple: disconnect, > reinstall from scratch, set new passwords for all accounts, apply > security audits. Sorry. > > >> We have gotten rid of our open relay and also the test / test >>account. > > > I believe, a proper action could be to use any automated tool for > internal password auditing. There is a plenty of security tools being > able to detect accounts with weak passwords. Any external test will not > be so effective and can miss something important. > > best, > Alexey > DSBL volunteer > > > >