A breakin at Carhart.com

Apparently someone out in computer land believes that Carhart.com is interesting enough to risk a lawsuit and prosecution, in order to break in and look around.


Carhart.com has been broken into twice.

The first time, a shell user exploited an undetected vulnerability, and gained root for a couple of hours. That was back in late 1996. Since then, users have been forced to undergo significantly more scrutiny before being granted access to this system.

In early October of 1997, someone in Iceland, from host spot55.centrum.is, managed
to gain access to Carhart.com without having an existing account. He was not very bright, leaving behind untouched log files, as well as a history file documenting exactly what he did here. However, even an idiot with a little bit of resourcefulness can gain root access from a shell account.

Mr. Icelandic Hacker had complete (root) access to all files on Carhart.com for 45 minutes. Fortunately, this loser didn't choose to damage any files. Although data on Carhart.com is protected by backup, it was not needed this time.

We at Carhart.com take security very seriously. Therefore, we have implemented basic firewalling, to prevent connections from unknown hosts. For more information, go back to the previous page


Copyright © 1997-99 Allan Carhart
Last Updated: 01/21/99 at 16:49:38 PM
Questions?   email me
Back to Home Page