This workstation compromised... Not sure how, but...

Scott Elcomb psema4-Re5JQEeQqe8AvxtiuMwx3w at public.gmane.org
Wed Nov 15 23:04:41 UTC 2006


I'm certainly open to any ideas.  Here's what I know so far:

#1 - On boot, non-root user id/passwd that has been in use for > 1
year is not working.

#2 - Using a virtual console, login as root and running passwd for the
workstation id, changed passwd for workstation id.

#3 - New password does _not_ work for associated id.

#4 - New password _does work_ for root.

I am assuming this workstation is compromised, and until resolved I
will be using other hardware(s) available to me.  Any suggestions,
ideas, thoughts would be welcome.  I really don't know how (!?!) this
workstation could have been influenced by outside forces since I'm
fairly certain of the integrity of at least 3 layers of security
between this workstation and the internet.  This includes firewall's
and routers.

-- 
Scott Elcomb
http://atomos.sourceforge.net/
http://search.cpan.org/~selcomb/SAL-3.03/
http://psema4.googlepages.com/

"They that can give up essential liberty to obtain a little temporary
safety deserve neither liberty nor safety."

  - Benjamin Franklin

'"A lie can travel halfway around the world while the truth is putting
on its shoes."

  - Mark Twain
--
The Toronto Linux Users Group.      Meetings: http://gtalug.org/
TLUG requests: Linux topics, No HTML, wrap text below 80 columns
How to UNSUBSCRIBE: http://gtalug.org/wiki/Mailing_lists





More information about the Legacy mailing list