Privacy and Security Notice

Archived Messages for LINUX-USERS_1997@cebaf.gov: FYI on Attack on Redhat Linux

FYI on Attack on Redhat Linux

Roy Whitney (whitney@CEBAF.GOV)
Wed, 23 Jul 1997 15:24:08 -0400

Date: Wed, 23 Jul 1997 11:17:55 -0700 (PDT)
From: ciac@tholia.llnl.gov (CIAC Mail User)
Subject: High Priority from CIAC
To: ciac-doe@tholia.llnl.gov

PGP signed message - the signature hasn't been checked

All DOE Constituents:

Just recently, a DOE site machine was compromised. The operating
system on that machine was Redhat Linux. CIAC believes that the hacker
entered through a well documented security hole. The scripts to exploit
this vulnerability have been made publicly available on Bugtraq. This
particular hacker is very familiar with hacking techniques and is good
at hiding himself. He is targeting high tech sites and the law
enforcement is envolved. CIAC recommends that all DOE sites running
any distribution of Linux implement the patches mention in CIAC
bulletins H-46 and recently released H-86. If you notice any strange
activities or if you have any questions, please contact CIAC as soon
as possible.

CIAC