Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Full-disclosure] SSH brute force blocking tool |
|---|---|
| Date: | Tue, 28 Nov 2006 11:59:43 -0500 |
On Tue, Nov 28, 2006 at 04:02:36PM +0000, Tavis Ormandy wrote: I notice you also havnt solved the local privilege escalation, this can be abused by local users to gain root by attempting to login with the username set to a valid passwd entry and then winning the race condition by creating a symlink to the system passwd file (of course, there are dozens of other attacks).
Thanks, Tavis.
Nov 27 16:31:21 local sshd[67010]: Illegal user dd from 213.134.128.227
awk '($5=="Illegal"||$6=="Illegal")&&$9=="from"{print $10}'But before you shoot back let me send your response for you:
"Someone could log in using: "Illegal User foo from$OWNIPADDRESS"@host which would make an entry:
Nov 27 16:31:21 local sshd[67010]: Illegal user dd from Illegal User
foo from $OWNIPADDRESS 213.134.128.227"
Sorry can't help you there.
The happiness of society is the end of government. John Adams
smime.p7s
Description: S/MIME Cryptographic Signature
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| Previous by Date: | Re: [Full-disclosure] SSH brute force blocking tool, J. Oquendo |
|---|---|
| Next by Date: | Re: [Full-disclosure] Sasser, jam |
| Previous by Thread: | Re: [Full-disclosure] SSH brute force blocking tool, Tavis Ormandy |
| Next by Thread: | Re: [Full-disclosure] SSH brute force blocking tool, Tavis Ormandy |
| Indexes: | [Date] [Thread] [Top] [All Lists] |