RE: 12.177.9.5

"David Cornett" <[email protected]>
Newsgroups gmane.mail.spam.dsbl.admin
Message-ID <200509140916620.SM01616@david0105>
Unfortunately backup is created with backup exec.  Fortunately the only
ports we have open are actually allowed are imail and icmp.  Remote access
port 3389 is not open.  So we should be ok.  Fortunately most of the mail
accounts on that server will be moved off due to a change in our
organization's name.  Which allowed us to purchase a new server to use for
mail.  


David Cornett

-----Original Message-----
From: Alexey Lobanov [mailto:[email protected]] 
Sent: Wednesday, September 14, 2005 9:05 AM
To: David Cornett
Cc: [email protected]
Subject: Re: [DSBL-Contact] 12.177.9.5

Hello.

On 14/09/05 17:14, David Cornett wrote:

> The accounts you have mentioned were unfortunately created for test
purposes
> by us.

To my experience, "backup" with administrative rights and default
password "backup" is autocreated by some [brain-damaged] backup software
for MS-Windows. Tou are not the first victim.  The real question is how
long ago was it done? Have anyone used this account through remote
desktop, web access or so on, to set up control over your host? I would
assume that it was done if this account existed more than a week or so.

>  We have, as of yesterday, gone through our entire user list.  If you
> would, go ahead and run the test for me one more time.  We are also going
to
> the extent of sending out a mandatory password change to all of our users.

Please note that both compromised accouns were not related to any real
users.

Anyway, the standard test is over, and nothing more was found.

Best,
Alexey


> And there will be some password rules applied to them.
> 
> -----Original Message-----
> From: Alexey Lobanov [mailto:[email protected]] 
> Sent: Tuesday, September 13, 2005 8:44 AM
> To: David Cornett
> Cc: [email protected]
> Subject: Re: [DSBL-Contact] 12.177.9.5
> 
> Hello.
> 
> On 09/13/2005 05:33 PM, David Cornett wrote:
> 
> 
>>Is there any testing process that we can request before we try your
> 
> removal
> 
>>process.
> 
> 
> This maillist is a right place for this request. The standard test based
> on real spammer activity is in progress now.
> 
> ...Oops. It had an effect:
> 
> Server accepted message
> AUTH=cram-md5 USER=backup PASS=backup IP=12.177.9.5
> 
> The situation is much more serious than an open relay. In difference
> from "test", "backup" is an administrative account. It is VERY POSSIBLE
> that whole system has been compromised and backdoored already through
> this account. The practical recommendation is simple: disconnect,
> reinstall from scratch, set new passwords for all accounts, apply
> security audits. Sorry.
> 
> 
>> We have gotten rid of our open relay and also the test / test
>>account.
> 
> 
> I believe, a proper action could be to use any automated tool for
> internal password auditing. There is a plenty of security tools being
> able to detect accounts with weak passwords. Any external test will not
> be so effective and can miss something important.
> 
> best,
> Alexey
> DSBL volunteer
> 
> 
> 
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.