Rooted

"Jason C. Wells" <[email protected]>
Newsgroups gmane.os.freebsd.chat
Message-ID <[email protected]>
For the second time in my life I've been rooted. I found a 
barbut.bsd.core file and a talkng file in my /root directory. Barbut is 
some sort of binary that a webserver hack seems to download and run 
after a broken module provides access. That's bothersome enough.

But the very bothersome part is that I do not run any services on this 
box beyond what is needed to provide packet filtering and ftp-proxy. I 
have all accounts disabled. I only login after booting to single user 
mode on the console. I'm looking at the security advisories and I don't 
see one that seems to apply to my 8.2 system in my configuration.

So, short of an exploit in the network stack, pf, and ftp-proxy, what is 
a possible attack vector?

Regarding the security advisory lingo, does "unprivileged user" mean a 
remote attacker? Most (all?) of the advisories seem to involve local 
exploits or exploitable services.

Regards,
Jason C. Wells
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-chat
To unsubscribe, send any mail to "[email protected]"
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.