2001-06-16 02:51:26+00 by TC 2 comments

Bruce Schneier is a pretty nice guy although a bit suspicious, anyhow he has given permission to post snipets of his cryptogram news letter provided he is credited and linked So this little bit of info made the hair on the back of my neck stand up...

"The results are fascinating. A random computer on the Internet is scanned dozens of times a day. The life expectancy of a default installation of Red Hat 6.2 server, or the time before someone successfully hacks it, is less than 72 hours. A common home user setup, with Windows 98 and file sharing enabled, was hacked five times in four days. Systems are subjected to NetBIOS scans an average of 17 times a day. And the fastest time for a server being hacked: 15 minutes after plugging it into the network."

#Comment made: 2002-02-21 05:31:50+00 by: meuon

Our record is under 2 days for a normal WinNT 4.0 server install to be hacked, no DNS pointing to it or anything, it was discovered and cracked wide open. Linux machines... funny, I have a honeypot machine with a RedHat 7.0 and a known easy to nail named that has survived for weeks.. just waiting to be nailed. Hmm...

#Comment made: 2002-02-21 05:31:51+00 by: TC

Interesting. Did you relax the firewall on the RH 7.0 machine? It defaults pretty high on install. Second do you use your Honeypot as a decoy (does that even make sense?) or are you a security person observing "les hackeaurs" in the glass box?