Traduisez - Übersetzen - Traduzca - Traduza - Tradurre - Translate

VanLUG Email Archive

Re: Why Do Hackers Do This?

Brian Edmonds
01 Oct 1998 08:27:30 -0700

Raymond D Mereniuk <
> writes:
> But, why would they disable IMAPD in the first place??

Good question. They could have been using a rootkit that did it for
them, and they really had no clue.

One Linux machine I manage was compromised last summer via a named
exploit, and the moron uploaded a root kit. I wouldn't have noticed
immediately except that the kit replaced the qpopper inetd config with a
line for ipop3d, which I hadn't configured, and thus no one could read
mail.

I say morons, as the cracker (note, not hacker) didn't actually get very
far on the system. The rootkit came mainly as source, and that machine
doesn't have a compiler. :)

Brian.