Odyssey

13 Aug, 2005

NC State webmail service compromised

Posted by: Gargs In: Tech and Culture

One of last week’s major event was the compromise of the NCSU Webmail system by hackers. What is surprising to me is the fact that the hackers had an IRC server running on 2 webmail servers for about 5 days before the IT Department staff noticed that the attackers might have captured user passwords.

The NCSU ITD system news bulletin has more information on the event. The NCSU password change facility was bogged down due to excessive network load after emails were sent to those that might have been affected by the exploit.

It seems that the attach was based on an April 2005 advisory posted on the Internet. It is named “Cacti Remote Command Execution Vulnerability”, and basically exposes vulnerability in the Cacti graphing tool. Cacti is a an RRDtool based package that uses mySQL databases to record various statistics about the network/server.

It is amazing to find out in conversations that some people do not change their passwords regularly, or have really funny password management tactics. Some people still use their SSN as passwords. Everyone should follow the guidelines on this website to choose passwords !

No Responses to "NC State webmail service compromised"

Comment Form

Categories

 

August 2005
M T W T F S S
« Jul   Sep »
1234567
891011121314
15161718192021
22232425262728
293031  

  • Compaq akkus: Thanks for your exciting article. One other problem is that mesothelioma cancer is generally attributable to the breathing of materials from asbestos,
  • Leisha: Wow, I have almost every film you talk about on your site. I don't have Tare Zameen Par because I can't find it in the Holand yet. I have not seen Raa
  • work-from-home: I see a lot of good content in phoenix.gargs.com ! earn money online

About

This is an example of a WordPress page, you could edit this to put information about yourself or your site so readers know where you are coming from.