[Nevis-linux] Password change

William Seligman seligman at nevis.columbia.edu
Wed Sep 3 13:26:42 EDT 2008


There was a recent security incident at Nevis.  I believe I have the matter 
under control, and I don't have any evidence that the attacker obtained any of 
our passwords, but:

- the attacker was running a keypress-monitor on some of the Nevis servers;

- the attacker had access to the encrypted password file on our main 
administrative server.

For that reason, I must ask that everyone with an account at Nevis change their 
passwords.  Just login to any one of the systems here and use the "yppasswd" 
command.

Please read the following web page, which includes some tips on how to create a 
good password:

<http://www.nevis.columbia.edu/software/security.html>

-- 
Bill Seligman             | Phone: (914) 591-2823
Nevis Labs, Columbia Univ | mailto://seligman@nevis.columbia.edu
PO Box 137                | http://www.nevis.columbia.edu/~seligman/
Irvington NY 10533 USA    | XDI: http://public.xdi.org/=william.seligman
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 3277 bytes
Desc: S/MIME Cryptographic Signature
Url : http://listserv.nevis.columbia.edu/pipermail/nevis-linux/attachments/20080903/ded86129/attachment.bin 


More information about the Nevis-linux mailing list