Re: hacked box research

From: Hugo van der Kooij (hvdkooijat_private)
Date: Sun Jun 24 2001 - 22:29:03 PDT

  • Next message: William Enestvedt: "RE: netbios scanning coming from IANA's internal class B...?"

    On Fri, 22 Jun 2001, Lowell wrote:
    
    > What hackers did:
    > Fed in the Lion worm to deface index pages.
    > Attempted to gain total control of router by changing vty to 1 and they were
    > going to be the one!
    > once we disallowed all vty programming they began a dos attack
    >
    > The question I as wondering was does anyone know how the were able to get
    > into the router? What is a excessive collision?
    
    I must assume you are referring to a Cisco router (Some vunerabilities are
    known with some of the IOS versions like the SNMP one.)
    
    If you check the archives of the bugtraq mailinglist you will see several
    messages regarding Cisco vunerabilities.
    
    Hugo.
    
    -- 
    All email send to me is bound to the rules described on my homepage.
        hvdkooijat_private		http://hvdkooij.xs4all.nl/
    	    Don't meddle in the affairs of sysadmins,
    	    for they are subtle and quick to anger.
    



    This archive was generated by hypermail 2b30 : Mon Jun 25 2001 - 06:24:10 PDT