|
![]() ![]() |
CERT® Advisory CA-1991-03 Unauthorized Password Change Requests Via Mail MessagesOriginal issue date: April 4, 1991Last revised: September 18, 1997 Attached copyright statement A complete revision history is at the end of this file. I. DescriptionThe Computer Emergency Response Team/Coordination Center (CERT/CC) has received a number of incident reports concerning the receipt of mail instructing the user to immediately change his/her password. The user is further instructed to change the password to one that is specified in the mail message.These mail messages can be made to look as if they have been sent from a site administrator or root. In reality, they may have been sent by an individual at a remote site, who is trying to gain access to the local machine via the user's account. Several variations of these mail messages are circulating via the Internet community. We are including one such example at the end of this advisory. II. ImpactAn intruder can gain access to a system through the unauthorized use of the (possibly privileged) accounts whose passwords have been changed.II. SolutionThe CERT/CC recommends the following actions:
SAMPLE MAIL MESSAGE as received by the CERT (including spelling errors, etc.)
:
{mail header which may or may not be local}
:
This is the system administration:
Because of security faults, we request that you change your password to "systest001". This change is MANDATORY and should be done IMMEDIATLY. You can make this change by typing "passwd" at the shell prompt. Then, follow the directions from there on. Again, this change should be done IMMEDIATLY. We will inform you when to change your password back to normal, which should not be longer than ten minutes. Thank you for your cooperation, The system administration (root) END OF SAMPLE MAIL MESSAGE This document is available from: http://www.cert.org/advisories/CA-1991-03.html CERT/CC Contact Information
Phone: +1 412-268-7090 (24-hour hotline) Fax: +1 412-268-6989 Postal address: CERT/CC personnel answer the hotline 08:00-17:00 EST(GMT-5) / EDT(GMT-4) Monday through Friday; they are on call for emergencies during other hours, on U.S. holidays, and on weekends. Using encryptionWe strongly urge you to encrypt sensitive information sent by email. Our public PGP key is available from If you prefer to use DES, please call the CERT hotline for more information. Getting security informationCERT publications and other security information are available from our web site
* "CERT" and "CERT Coordination Center" are registered in the U.S. Patent and Trademark Office.
NO WARRANTY Conditions for use, disclaimers, and sponsorship information
Copyright 1991 Carnegie Mellon University. Revision History September 18,1997 Attached Copyright Statement |








