[SAC] LDAP user account "steve" compromised

Martin Spott Martin.Spott at mgras.net
Thu Aug 8 02:14:02 PDT 2013


Hi Steve,
apparently someone somehow managed to guess your password, logged into
one of those machines which provide shell login to OSGeo "shell" users
and subsequently changed your password at 2013-08-06 13:54:43 UTC.
Finally the affected machine was used to run pscan2/scanssh to randomly
scan SSH access on other systems.

Your password is now safe because I set it to a random string and I
suggest you negotiate with FrankW to set a new password.  I invite
everybody to join me in checking the other OSGeo servers for similar
abuse of the "steve" or other logins.

Cheers,
	Martin.
-- 
 Unix _IS_ user friendly - it's just selective about who its friends are !
--------------------------------------------------------------------------


More information about the Sac mailing list