oldbloke: (Default)
posted by [personal profile] oldbloke at 01:53pm on 25/02/2005
We've got HackerDefender.gen.c on the loose here. Several of our servers, one or two of other people's, and a few workstations, mostly here.
Wonder how it got in? Wonder how it spread around?
For workstations we're telling people to re-install Windows, so my bit's easy.
For server's, Shaz is telling people how to make it reveal itself so it can be deleted (system internals utility rootkitrevealer), though VirusScan will get it in Safe Mode. Then he wants all pws changed and a security audit of the machine. He knows his stuff - so many people here don't even think about security until it's too late. The campus perimiter firewall is still on "only shut down threats that have caused problems" instead of "only open what's required".
"People need to work from home" - well make them use ssh and validate by IP, not just passwords, FFS.
oldbloke: (Default)

RBL

posted by [personal profile] oldbloke at 10:54pm on 25/02/2005
How do you get out of the JANET RBL? Man Uni seesm to think my org.uk domain is a spamhaus... all it ever does is forward mail from my org.uk address to my uni address! Unless somebody "borrowed" it...

May

SunMonTueWedThuFriSat
        1
 
2
 
3
 
4
 
5
 
6
 
7
 
8
 
9
 
10
 
11
 
12
 
13
 
14
 
15
 
16
 
17
 
18
 
19
 
20
 
21
 
22
 
23
 
24
 
25
 
26
 
27
 
28
 
29 30
 
31