Preface: rlogin -froot backdoorLogo -Internet Security Systems

rlogin -froot backdoor

advICE :Intrusions : 2002101
 FAQ
Oh my gosh, I'm being HACKED!!!
How do I report the hacker to my ISP?
I'm seeing lots of attacks, is this normal?
The intruder is trying to attack an older version of the rlogin server which allows remote login as root without a password. The command would look like:
	 % rlogin victim.example.net -l -froot
	 #
This results in a root prompt on the remote system. Many older AIX systems, Linux Slackware 3.1, RedHat 2.1, and others are affected.

This attack can also be directed at the rsh service.

 more information
BugtraqID: 458   AIX login(1) Vulnerability
 
rlogin exploits  
 
CERT: CA-94.09.bin.login.vulnerability   Topic: /bin/login Vulnerability
 
CVE-1999-0113   Rlogin root access through -froot parameter
 
 
Version appeared:  

Privacy Policy |  Copyright Info