The Cellar  

Go Back   The Cellar > Main > The Internet
FAQ Community Calendar Today's Posts Search

The Internet Web sites, web development, email, chat, bandwidth, the net and society

Reply
 
Thread Tools Display Modes
Old 06-05-2001, 06:27 PM   #1
jaguar
whig
 
Join Date: Apr 2001
Posts: 5,075
Nope, he was just arrogant/bored.
BUt yea, i've heard of people doing that *many* times. They had one at my school for a short while but it took around 5 days for kids to start picking holes in the pissweak security so the scrapped the idea.
__________________
Good friends, good books and a sleepy conscience: this is the ideal life.
- Twain
jaguar is offline   Reply With Quote
Old 06-11-2001, 10:13 PM   #2
leif
Confounded Conjuror
 
Join Date: May 2001
Location: N. California
Posts: 33
I just wanted to throw in my $0.02 security tale...

The local ISP in my area got its shell server's ssh client compromised, and didn't notice for some time. Hundreds of passwords were recorded including several of my own.

Another server that I had a shell account on got hacked a couple months ago, also an ssh hack I believe, and the cracker came in through my account. I was shocked, since I don't connect from anywhere but work, home, and the ISP's shell server, and I only use ssh. It wasn't until much later when the ISP realized that they had been compromised that I realized how my password got stolen. As it turns out, a friend of mine's J.C. shell account also got hacked. He ended up with his account terminated, and the teacher threatened to throw him out of the class for hacking... He later found out this was because there was some sort of root kit in his home directory. He, also, had been connecting via the ISP's shell server using the compromised ssh client.

All in all it was a real eye-opener for me and a lot of other people. Persumably a single person caused so much damage, not just online but in various people's lives as well. Stupid cracks like this seem like a minor annoyance until you get victimized by one.
leif is offline   Reply With Quote
Old 06-12-2001, 03:18 AM   #3
jaguar
whig
 
Join Date: Apr 2001
Posts: 5,075
With the shear lack of water-tight security around tales like yours scare me, while I’ve never suffered a major crack a recent story about the *almost* cracking of a Californian power company (what power is there to stop?) to the level of control computers scared the shit out of me, cyber terrorism becomes real-world terrorism, i can see combined cyber-real world terrorists attacks with essential services being knocked off...
Scary stuff, I think the world needs more OpenBSD and less stupid admins.

__________________
Good friends, good books and a sleepy conscience: this is the ideal life.
- Twain
jaguar is offline   Reply With Quote
Old 06-12-2001, 01:19 PM   #4
tw
Read? I only know how to write.
 
Join Date: Jan 2001
Posts: 11,933
Re: Denial of service attack dissected

Quote:
Originally posted by leif
I just wanted to throw in my $0.02 security tale...

... As it turns out, a friend of mine's J.C. shell account also got hacked. He ended up with his account terminated, and the teacher threatened to throw him out of the class for hacking... He later found out this was because there was some sort of root kit in his home directory. He, also, had been connecting via the ISP's shell server using the compromised ssh client.
I believe the concensus was that personal ID verification is not a problem in America AND it will not get worse. It is the general trend. We have plenty of databases to trace what you supposidly did, but we have no fundamental method so that you and only you can confirm you are who you say you are AND we have no methods so that you can confirm that your ID is safe and uncompromised.

OK, maybe a system could not be created to avoid this particular shell ID and Password violation. But we have virtually no systems for you only to prove you are you AND to verify that others have not compromised your ID. Presently another can steal your ID, you would never know, AND you would suffer consequences from powers that would first look to blame you - all because we don't have a National ID Confirmation system.


[Edited by tw on 06-12-2001 at 02:22 PM]
tw is offline   Reply With Quote
Old 06-13-2001, 04:56 AM   #5
jaguar
whig
 
Join Date: Apr 2001
Posts: 5,075
Yes, i have to agree, i mean have a *BIG* problem with the govt watching me, but i don't mind being given a number, it doesn’t achieve anything in itself.
The only thing that strikes me is what exactly does it achieve, its how it’s checked that it’s the right person, i.e., verification that is the tricky bit, particularly on the net were *nothing* is secure.

__________________
Good friends, good books and a sleepy conscience: this is the ideal life.
- Twain
jaguar is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

All times are GMT -5. The time now is 07:48 AM.


Powered by: vBulletin Version 3.8.1
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.