Hack check

From: Joe Fletcher <joe_at_meng.ucl.ac.uk>
Date: Mon, 13 Sep 1999 13:45:12 +0111

Hi All,

Can someone clear up a nagging doubt for me please. We have a group of
systems here and their owner is worried about them being hacked.
Some SUN systems in their group have been done over and we want to check
the Alphas.

One thing I've noticed is that on their systems there are records
for login by the account LOGIN on terminal dtremote. This dtremote links to
/dev/null. Now none of the other Alpha systems I've checked (so far) have this
link for dtremote. Can anyone tell me if this link is a known feature
(of CDE I would guess) or whether I should do something about it.

Also, if anyone knows of any other tell-tale signs of hacks to look for I'd
appreciate the info.

TIA

Joe.
Received on Mon Sep 13 1999 - 12:46:54 NZST

This archive was generated by hypermail 2.4.0 : Wed Nov 08 2023 - 11:53:39 NZDT