Oct. 28th, 2001

1337

Oct. 28th, 2001 10:07 am
prog: (Default)
Well, I just found a good reason to use one's alternate blog: the machine hosting one's main blog gets cracked by k1dd1ez, and you have to pull the machine off the net, and you have no physical access to the machine until Monday, at which time you'll have to reinstall the whole operating system to guarantee a successful exorcism.

Yep, that'll do it.

I am lucky to have both clueful friends and clueless (or perhaps just unmotivated) attackers in this matter. I don't know when the compromise occurred -- I have reason to suspect it happened more than a week ago -- but I started receiving mail from unknown sysadmins last night, saying that they were receiving repeated, failed ssh login attempts originating from my IP. This morning, after I sent out a call for advice, my BOFH buddy Noah found a patched ssh daemon running on an insanely numbered port, and some other service living on port 12345, which I certainly didn't launch.

Since everything else on my machine looks fine, the blackhats didn't seem to do much mischief
outside of using my poor box as a platform for further attacks, and for this I am lucky. However, there's no telling what else they may have accomplished more subtly, so down it all goes.

I guess I needed to be taught a lesson about Internet security, and the lesson could have been much harder -- thanks heavens they didn't touch any of my or my friends' data! However, the timing could have been a lot better, as I have to be moving sometime this week, and that's enough of a timesink in itself. I'm prepared to be without my vanity domain for several days. Sigh.

Wilfredo

Oct. 28th, 2001 11:30 am
prog: (Default)
An upshot of losing access to my Linux box for awhile is that I find myself encouraged to explore the arcana of my iBook, which runs OS X -- the operating system one cohort describes as FreeBSD with plastic no-slip bathtub flowers slapped all over it. So it is UNIX, really, and it's happy enough to admit as much, and though the face it presents most of the time is pure, kandy-koated Apple GUI goo, it doesn't flinch when you launch the Terminal application and plunge both arms to the elbow through the console window and into its guts.

I'm by no means a Unix expert, but I like to think I more or less know my way around, and I'm finding some neat stuff already. Allow me to quote from my laptop's factory-default /etc/rc file, edited by Wilfredo Sanchez, a Darwin head honcho whom I actually had the pleasure of meeting at a MacWorld Expo that I (bizarrely) spoke at last year:
##
# Set shell to ignore Control-C, etc.
# Prevent lusers from shooting themselves in the foot.
##

Dude, this is a user-readable file, authored by an Apple employee, front-and-center in every installation of Mac OS X. Yay.

August 2022

S M T W T F S
 123456
78910111213
14151617181920
21222324252627
28 293031   

Most Popular Tags

Page Summary

Style Credit

Expand Cut Tags

No cut tags
Page generated Aug. 10th, 2025 05:31 am
Powered by Dreamwidth Studios