UMKC Hacked!

Jason Clinton me at jasonclinton.com
Mon Jan 12 19:37:20 CST 2004


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Charles, Joshua Micah (UMKC-Student) wrote:

| Got to work on campus this morning and faced another harsh reality of
| Microsoft technology.  Over the weekend, somebody hacked into the
| servers, and EVERYONES password was compromised.  Hmm, it will be
| interesting to discover if any lawsuits come out of this one.

I have learned more. It appears that one of the network admins had an
incredibly weak password or the attacker somehow obtained the password
in another way. An entire password list was downloaded but I haven't
gotten an answer on whether or not the list was plain text or shadowed,
if it's the former, the full disclosures mailing list should probably be
notified since UMKC was/is hosting some FTP sites.

| In other news, it has been brought to my attention that at one of my
| jobs, they are looking for a full time sys admin.  Not sure about the
| qualifications.  For more information e-mail pittst at umkc.edu, or look at
| the online database (as long as that hasn't been compromised also ;) )

It it posted on the official HRes site yet? I didn't see it.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFAAvdttSqjk42zvwkRAlJQAJ9SRdI+7+MXGVW6cAZ4sWYlRdmxhQCfVOe/
ZRaMoI/HvdBUOvgU1RourJU=
=o7YQ
-----END PGP SIGNATURE-----




More information about the Kclug mailing list