Odyssey

13 Aug, 2005

NC State webmail service compromised

Posted by: Gargs In: Tech and Culture

One of last week’s major event was the compromise of the NCSU Webmail system by hackers. What is surprising to me is the fact that the hackers had an IRC server running on 2 webmail servers for about 5 days before the IT Department staff noticed that the attackers might have captured user passwords.

The NCSU ITD system news bulletin has more information on the event. The NCSU password change facility was bogged down due to excessive network load after emails were sent to those that might have been affected by the exploit.

It seems that the attach was based on an April 2005 advisory posted on the Internet. It is named “Cacti Remote Command Execution Vulnerability”, and basically exposes vulnerability in the Cacti graphing tool. Cacti is a an RRDtool based package that uses mySQL databases to record various statistics about the network/server.

It is amazing to find out in conversations that some people do not change their passwords regularly, or have really funny password management tactics. Some people still use their SSN as passwords. Everyone should follow the guidelines on this website to choose passwords !

No Responses to "NC State webmail service compromised"

Comment Form

Categories

 

August 2005
M T W T F S S
« Jul   Sep »
1234567
891011121314
15161718192021
22232425262728
293031  

  • Madhu: hyderabadgift.com helps you to order online to send flowers to Hyderabad, Gifts to Hyderabad, Birthday gifts to Hyderabad, Anniversary Gifts to Hydera
  • Prernefog: demeanour viagra joining
  • Fabbairejes: Hi people As a fresh phoenix.gargs.com user i just wanted to say hello to everyone else who uses this forum :D

About

This is an example of a WordPress page, you could edit this to put information about yourself or your site so readers know where you are coming from.