Your message dated Wed, 18 Oct 2006 22:07:52 +0100
with message-id <[EMAIL PROTECTED]>
and subject line Closing non-issue
has caused the attached Bug report to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere. Please contact me immediately.)
Debian bug tracking system administrator
(administrator, Debian Bugs database)
--- Begin Message ---
Package: security.debian.org
Severity: critical
Tags: security
Justification: root security hole
"Enlarge your d1ck" spammers are using a security hole in debian :
all zombified system I have tested are running apache 2.054/debian PHP 4.3.10.16
the payload of the trojan began about on may the 23th - I could manage and fill
informations about that at that date, I'm sorry not to have done that before.
see
<news:[EMAIL PROTECTED]>
I received the spam on may the 23th. I found somethin weird in spamvertized
site DNS but I scanned some zombified machine and did not look at http headers
of zombified machines - I should.
See <news:[EMAIL PROTECTED]>
Most probably zombified host dns-claim to be the spamvertized sites' SOA and
(when admin did not clean their webspace :/)and their http redirects to
probably more rotten
machine that host the spammer's pages
-- System Information:
Debian Release: testing/unstable
APT prefers unstable
APT policy: (500, 'unstable'), (500, 'testing'), (500, 'stable'), (1,
'experimental')
Architecture: i386 (i686)
Shell: /bin/sh linked to /bin/bash
Kernel: Linux 2.6.16-2-k7
Locale: [EMAIL PROTECTED], [EMAIL PROTECTED] (charmap=ISO-8859-15)
--- End Message ---
--- Begin Message ---
Not to do with us, closing
Neil
--
02:14:04 <stockholm> crap. my squirrelmail does not work
02:14:07 <stockholm> Maulkin: ping
signature.asc
Description: Digital signature
--- End Message ---