SI
SI
discoversearch

We've detected that you're using an ad content blocking browser plug-in or feature. Ads provide a critical source of revenue to the continued operation of Silicon Investor.  We ask that you disable ad blocking while on Silicon Investor in the best interests of our community.  If you are not using an ad blocker but are still receiving this message, make sure your browser's tracking protection is set to the 'standard' level.
Pastimes : Internet Security/Privacy Issues and Solutions

 Public ReplyPrvt ReplyMark as Last ReadFilePrevious 10Next 10PreviousNext  
To: PJ Strifas who wrote (130)4/5/2001 12:30:52 AM
From: Jim Burnham  Read Replies (2) of 210
 
I got hacked.

I have a unix machine on the internet and today I found out that my machine had been hacked into. After about 8 hours of work I was able to remove the damage. But wow, the damage was everywhere.

There was a program running with an open socket. Could be used to fake email, forward some of my passwords, hack other sites, create user accounts, etc.

The program was cleverly put into the start up files so that it would start up on a reboot of the system.

About 6 different critical files were replaced with new and mysterious versions. The results were that every typed in password could have been saved or forwarded to other machine on the internet. Files could be hidden on my system (not normally the case), and that files could be made un-erasable on my system (also not normally the case).

All in all, I don't think it was a professional hacker. After all, I did find out it happened. And I was able to track what he/she did. But this person had a very nice set of tools available to use and knew a few clever tricks. I'm willing to call it even since he/she did me the favor of leaving a set of these tools on my system. The reason I don't think this guy was a professional hacker (in the talent sense of the term only), is that most of his tool had help options available.

I already have a few ideas for tracking down the next nutcase that tries that again. Time to email my users to change their passwords pronto.

Jim
Report TOU ViolationShare This Post
 Public ReplyPrvt ReplyMark as Last ReadFilePrevious 10Next 10PreviousNext