Page 1 of 1

HACKED

Posted: 01 Dec 2005 05:18
by Guest
http://www.videolan.org HACKED.

05:11 www-data@ganesh ~% uname -a
Linux ganesh 2.6.14-grsec #1 SMP Tue Nov 1 01:14:58 CET 2005 x86_64 GNU/Linux
05:11 www-data@ganesh ~% id
uid=33(www-data) gid=33(www-data) groups=33(www-data)
05:11 www-data@ganesh ~% w
05:11:39 up 9 days, 19:56, 1 user, load average: 1.03, 1.04, 0.98
USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT
videolan pts/0 zen.via.ecp.fr 23Nov05 2days 0.05s 0.05s -zsh

Posted: 01 Dec 2005 13:23
by Guest
Looks like the admined closed up the hole. Good job.

P.S. admin, I stole your sexy color prompt. :wink:

Posted: 01 Dec 2005 13:59
by zorglub
Hello,

Glad you enjoyed the color prompt. You can have a look at http://people.via.ecp.fr/~alexis/formation-linux/ that offers a different prompt for the root account, too bad you didn't see this one.

Thanks for the proof of concept anyway.

General note: VLC binaries were not affected by this attack.

Posted: 01 Dec 2005 20:04
by Guest
i am a videolan user, and would never want to destroy something like this. I'm glad you patched the system and were not found by a "malicious" attacker. Have a nice day!