home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!ogicse!uwm.edu!zaphod.mps.ohio-state.edu!saimiri.primate.wisc.edu!copper!cudnvr!dwing
- From: dwing@cudnvr.denver.colorado.edu (Dan Wing)
- Newsgroups: comp.security.misc
- Subject: Re: Forging E-mail from root to get users to change passwords
- Message-ID: <1992Nov9.214145.1@cudnvr.denver.colorado.edu>
- Date: 9 Nov 92 21:34:45 GMT
- Article-I.D.: cudnvr.1992Nov9.214145.1
- References: <82930@ut-emx.uucp> <ratner.720811773@ficus.cs.ucla.edu> <92309.193737CXF111@psuvm.psu.edu> <1992Nov5.174213.2370@mksol.dseg.ti.com>
- Sender: netnews@copper.denver.colorado.edu
- Lines: 31
-
- In article <1992Nov5.174213.2370@mksol.dseg.ti.com>, mccall@mksol.dseg.ti.com
- (fred j mccall 575-3539) writes:
-
- > In <92309.193737CXF111@psuvm.psu.edu> Charles Fee <CXF111@psuvm.psu.edu> writes:
- >
- >>Why would a hacker (who apparently has root access) need to tell users to
- >>change their password? On my system (Linux) all root has to do is wipe out
- >>the users' old password and then the account is free. You could then log in
- >>as that user without a password and run the passwd program to change it to
- >>whatever the cracker feels like doing.
- [...]
- > You don't even have to go through all this, if you already have root
- > access. Just use passwd from root with the username argument and you
- > can change it directly from root.
-
- A hacker would usually ask a user to change their password because the
- hacker *doesn't* have root access (at least, not yet). The hacker faked an
- Email address to make it look like it came from root - it didn't come from
- root.
-
- Also, if a hacker changes someone's password, the person will know it (the
- legitimate user can no longer login) and the legit user will call the
- the sysadmin and whine "I forgot my password" and the sysadmin will change it
- -- locking out the hacker. If a hacker wants to run 'stealth' on your system,
- it is a lot easier to use an already-existing username rather than create a
- new username or use your root login.
-
- My own comments and ideas, not those of my employer.
-
- -dan
- Internet: DWING@UH01.Colorado.EDU, or DWING@cudnvr.denver.colorado.edu
-