Advertisement
Guest User

HBGary: Online Smear Campaigns

a guest
Feb 11th, 2011
14,446
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.51 KB | None | 0 0
  1. HBGary E-mail Viewer
  2.  
  3.  
  4. Go back
  5.  
  6.  
  7. Original file: 27606
  8. click here to show this e-mail with HTML markup
  9. From: jussi jaakonaho <[email protected]>
  10. To: Greg Hoglund <[email protected]>
  11. Date: Sun, 6 Feb 2011 22:15:54 +0200
  12. Subject: Re: need to ssh into rootkit
  13. click here to show full headers
  14. Attachments: This e-mail does not have any attachments.
  15.  
  16.  
  17.  
  18. did you open something running on high port?
  19.  
  20.  
  21. On Feb 6, 2011, at 9:43 PM, Greg Hoglund wrote:
  22.  
  23. > ok let me know if you need me
  24. >
  25. > On 2/6/11, jussi jaakonaho <[email protected]> wrote:
  26. >> tnx.
  27. >> i am also connected to the box, seems some people have download problems -
  28. >> have figured earlier that some chinese used chinese chars on names of files,
  29. >> which then our filtering stripped off when putting db etc. so some db
  30. >> editing
  31. >>
  32. >>
  33. >> _jussi
  34. >>
  35. >> On Feb 6, 2011, at 9:36 PM, Greg Hoglund wrote:
  36. >>
  37. >>> ok ill make sure to get you a new license asap.
  38. >>>
  39. >>> On 2/6/11, jussi jaakonaho <[email protected]> wrote:
  40. >>>> np.
  41. >>>> btw i did not shut down the firewall so it still protects with too many
  42. >>>> connections from same source address.
  43. >>>>
  44. >>>> i have also downloaded latest backups from /home/varmi to my homebox,
  45. >>>> just
  46. >>>> in case.
  47. >>>>
  48. >>>> oh, also seem my license is expiring for responder again. o:-) was
  49. >>>> thinking
  50. >>>> to put it into box with more memory.
  51. >>>>
  52. >>>> _jussi
  53. >>>>
  54. >>>> On Feb 6, 2011, at 9:26 PM, Greg Hoglund wrote:
  55. >>>>
  56. >>>>> yup im logged in thanks ill email you in a few, im backed up
  57. >>>>>
  58. >>>>> thanks
  59. >>>>>
  60. >>>>> On 2/6/11, jussi jaakonaho <[email protected]> wrote:
  61. >>>>>> nope. your account is named as hoglund
  62. >>>>>>
  63. >>>>>>
  64. >>>>>> On Feb 6, 2011, at 9:23 PM, Greg Hoglund wrote:
  65. >>>>>>
  66. >>>>>>> yes jussi thanks
  67. >>>>>>>
  68. >>>>>>> did you reset the user greg or?
  69. >>>>>>>
  70. >>>>>>> On 2/6/11, jussi jaakonaho <[email protected]> wrote:
  71. >>>>>>>> does it work now?
  72. >>>>>>>>
  73. >>>>>>>>
  74. >>>>>>>> On Feb 6, 2011, at 9:17 PM, Greg Hoglund wrote:
  75. >>>>>>>>
  76. >>>>>>>>> if i can squeeze out time maybe we can catch up.. ill be in germany
  77. >>>>>>>>> for a little bit.
  78. >>>>>>>>>
  79. >>>>>>>>> anyway I can't ssh into rootkit. you sure the ips still
  80. >>>>>>>>> 65.74.181.141?
  81. >>>>>>>>>
  82. >>>>>>>>> thanks
  83. >>>>>>>>>
  84. >>>>>>>>> On 2/6/11, jussi jaakonaho <[email protected]> wrote:
  85. >>>>>>>>>> ok,
  86. >>>>>>>>>> it should now accept from anywhere to 47152 as ssh. i am doing
  87. >>>>>>>>>> testing
  88. >>>>>>>>>> so
  89. >>>>>>>>>> that it works for sure.
  90. >>>>>>>>>> your password is changeme123
  91. >>>>>>>>>>
  92. >>>>>>>>>> i am online so just shoot me if you need something.
  93. >>>>>>>>>>
  94. >>>>>>>>>> in europe, but not in finland? :-)
  95. >>>>>>>>>>
  96. >>>>>>>>>> _jussi
  97. >>>>>>>>>>
  98. >>>>>>>>>> On Feb 6, 2011, at 9:08 PM, Greg Hoglund wrote:
  99. >>>>>>>>>>
  100. >>>>>>>>>>> no i dont have the public ip with me at the moment because im
  101. >>>>>>>>>>> ready
  102. >>>>>>>>>>> for a small meeting and im in a rush.
  103. >>>>>>>>>>>
  104. >>>>>>>>>>> if anything just reset my password to changeme123 and give me
  105. >>>>>>>>>>> public
  106. >>>>>>>>>>> ip and ill ssh in and reset my pw.
  107. >>>>>>>>>>>
  108. >>>>>>>>>>> thanks
  109. >>>>>>>>>>>
  110. >>>>>>>>>>> On 2/6/11, jussi jaakonaho <[email protected]> wrote:
  111. >>>>>>>>>>>> hi,
  112. >>>>>>>>>>>>
  113. >>>>>>>>>>>> do you have public ip? or should i just drop fw?
  114. >>>>>>>>>>>> and it is w0cky - tho no remote root access allowed
  115. >>>>>>>>>>>>
  116. >>>>>>>>>>>> On Feb 6, 2011, at 8:59 PM, Greg Hoglund wrote:
  117. >>>>>>>>>>>>
  118. >>>>>>>>>>>> _jussi
  119. >>>>>>>>>>>>
  120. >>>>>>>>>>>>
  121. >>>>>>>>>>>>> jussi
  122. >>>>
  123. >>>>
  124. >>
  125. >>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement