[bitfolk] Interesting email to "root" - possible exploit att…

Top Page

Reply to this message
Author: Alastair Sherringham
Date:  
Subject: [bitfolk] Interesting email to "root" - possible exploit attempt (failed hopefully)
No-nonsense VPS hosting<br>
</div></div><br>-----BEGIN PGP SIGNATURE-----<br>
Version: GnuPG v1.4.10 (GNU/Linux)<br>
<br>
iEYEAREDAAYFAk8lhdEACgkQIJm2TL8VSQuNuACeJ4/NnRkd7PIpt2r8xR89qat5<br>
p0wAoPRf532OB31flRB7E34Mdjk4ARa/<br>
=3Ds4s+<br>
-----END PGP SIGNATURE-----<br>
<br>_______________________________________________<br>
users mailing list<br>
<a href=3D"mailto:users@lists.bitfolk.com">users@???</a><br>
<a href=3D"https://lists.bitfolk.com/mailman/listinfo/users" target=3D"_bla=
nk">https://lists.bitfolk.com/mailman/listinfo/users</a><br>
<br></blockquote></div><br><br clear=3D"all"><br>-- <br><div>Keith Williams=
</div><div>=A0</div><div>
<p style=3D"margin-bottom:0cm">I can picture in my
mind a world without war, a world without hate. And I can picture us
attacking that world, because they&#39;d never expect it. </p><p style=3D"m=
argin-bottom:0cm">- Jack Handey</p>
</div><div>=A0</div><div>I&#39;m sick of following my dreams. I&#39;m just =
going to ask them where they&#39;re<br>going and hook up with them later.<b=
r> - Mitch Hedberg</div><div><br>=B7=D3=B4=D5=E4=B4=E9=B4=D5 =B7=D3=AA=D1=

=E8=C7=E4=B4=AA=D1=E8=C7</div><div><br></div>
<div>=A0</div>
<div>=A0</div><br>

--f46d0444ef0bfa090804b7aeb1a2--


From ian@??? Sun Jan 29 23:00:45 2012
Received: from semi-divine.com ([85.119.83.38] helo=topcat.semi-divine.com)
    by mail.bitfolk.com with esmtp (Exim 4.72)
    (envelope-from <ian@???>) id 1Rrdjp-0000g8-Ci
    for users@???; Sun, 29 Jan 2012 23:00:45 +0000
Received: from [192.168.0.23]
    (cpc3-nwrk4-2-0-cust250.12-1.cable.virginmedia.com [86.26.44.251])
    by topcat.semi-divine.com (Postfix) with ESMTPSA id 5AAB68420C
    for <users@???>; Sun, 29 Jan 2012 23:00:42 +0000 (UTC)
Message-ID: <4F25CF99.4070900@???>
Date: Sun, 29 Jan 2012 23:00:41 +0000
From: Ian <ian@???>
User-Agent: Mozilla/5.0 (X11; Linux x86_64;
    rv:9.0) Gecko/20111229 Thunderbird/9.0
MIME-Version: 1.0
To: users@???
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
X-Virus-Scanner: Scanned by ClamAV on mail.bitfolk.com at Sun,
    29 Jan 2012 23:00:45 +0000
X-SA-Exim-Connect-IP: 85.119.83.38
X-SA-Exim-Mail-From: ian@???
X-SA-Exim-Scanned: No (on mail.bitfolk.com); SAEximRunCond expanded to false
Subject: [bitfolk] IP renumbering
X-BeenThere: users@???
X-Mailman-Version: 2.1.11
Precedence: list
List-Id: Users of BitFolk hosting <users.lists.bitfolk.com>
List-Unsubscribe: <https://lists.bitfolk.com/mailman/options/users>,
    <mailto:users-request@lists.bitfolk.com?subject=unsubscribe>
List-Archive: <http://lists.bitfolk.com/lurker/list/users.html>
List-Post: <mailto:users@lists.bitfolk.com>
List-Help: <mailto:users-request@lists.bitfolk.com?subject=help>
List-Subscribe: <https://lists.bitfolk.com/mailman/listinfo/users>,
    <mailto:users-request@lists.bitfolk.com?subject=subscribe>
X-List-Received-Date: Sun, 29 Jan 2012 23:00:45 -0000


Hi,

Some of this was easy (changing where the slave DNSes got their info
from was a simple sed search and replace) and some tedious (changing all
the master DNS where because of needing to change the serial number for
all of them, this was done by hand via a control panel - if there was an
easier way, I am not sure I want to know now :) )

The one thing not mentioned on the wiki is that doing

> grep -r 212.13.19 *


in /etc now comes up with one hit, in ntp.conf:

> # and admin.curacao.bitfolk.com (nagios)
> restrict 212.13.194.71


so I changed that to 85.119.80.238 and 85.119.80.244 per the customer
information page on the website and restarted ntp.

Now I think it's just a case of waiting for the rest of the net to
notice the DNS changes...

Ian


From ian@??? Mon Jan 30 00:14:37 2012
Received: from semi-divine.com ([85.119.83.38] helo=topcat.semi-divine.com)
    by mail.bitfolk.com with esmtp (Exim 4.72)
    (envelope-from <ian