[OpenAFS] Is anyone else seeing this:

Brandon S. Allbery KF8NH allbery@ece.cmu.edu
Sat, 1 Mar 2008 11:57:51 -0500


On Mar 1, 2008, at 11:35 , Jeffrey Altman wrote:

> Steve Devine wrote:
>> http://www.msu.edu/~elizald2/viagra/order-viagra-overnight- 
>> delivery.html
>> I have disabled it but you get the idea,. This dir is chock-o- 
>> block full
>> of crap.
>> I believe this is the work of a bot that arrives initially to the the
>> user via a spam email.
>>
> If you are interested in knowing where the files are coming from turn
> on audit logs on the file servers.  That will erase all doubts.
>
> But lets make something absolutely clear.  If you have volumes that
> permit system:anyuser to write to it, there does not have to be any
> spam involved.  Any machine with any AFS client anywhere in the  
> world can write to the volume.  There is no need to send spam.

That said, this is probably not specific to AFS; I would suspect a  
garden-variety virus/worm that propagates itself via SMB shares.

-- 
brandon s. allbery [solaris,freebsd,perl,pugs,haskell] allbery@kf8nh.com
system administrator [openafs,heimdal,too many hats] allbery@ece.cmu.edu
electrical and computer engineering, carnegie mellon university    KF8NH