Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Miami backdoor, warning!

130 views
Skip to first unread message

Kirk Strauser

unread,
Dec 3, 1998, 3:00:00 AM12/3/98
to
David Gerber wrote:

>Miami has a backdoor and seems to have it for a long time.

Sigh. Do we HAVE to go through this every time those Digital Corruption
losers issue a "press release"?

>Some people actually managed to find how it works and started to steal
>passwords from people.

What's even MORE interesting is that plenty of these people are known
to use AmiTCP, or even Windows! It's rather fascinating how "they"
were able to crack Miami's non-existent backdoor on machines not
even running Miami.

>If you are on the list, change your password as quickly as possible, and
do
>not use Miami anymore.

Yes, let's cause a hysteria that results in one of the last and best Amiga
developers leaving the platform.

Get the facts before you post in the future. Until you know what you're
talking about, shut up.

Kirk Strauser
Member Team AMIGA


Gary Peake

unread,
Dec 3, 1998, 3:00:00 AM12/3/98
to
za...@deckpoint.ch scribed to us about Miami backdoor, warning! in
comp.sys.amiga.misc

>If you are on the list, change your password as quickly as possible, and do
>not use Miami anymore.

Amazing! You missed mine although several have TRIED to get into my computer?

Funny that ...

Sorry, David, I happen to think Holger is a fine person and will continue using
Miami. Besides, Miami seems pirate proof so far, to me ...

BTW, if you are so good at finding this backdoor, rather than just idiot stuff
that can be gleaned from irc, why no passwords? In essence, where's the
beef? No beef, no stringy noodles, nothing..

Did you get these with or without your using a pirated AmIRC key? Inquiring
minds want to know.

--

Gary Peake PLEASE NOTE NEW EMAIL ADDRESS!!

Team AMIGA
gpe...@owlsnet.net
http://www.owlsnet.net (coming soon)


David Gerber

unread,
Dec 4, 1998, 3:00:00 AM12/4/98
to
Miami has a backdoor and seems to have it for a long time. Some people

actually managed to find how it works and started to steal passwords from
people. It's very important to check if your login is on this list. I
intentionally removed the passwords from it to avoid security problems.

If you are on the list, change your password as quickly as possible, and do
not use Miami anymore.

[@@@ Part 1]

/\
/ \ ____
___________ __________ / \\ ____________/ |______
___\____ \_ __|__/__ \\/ _/ |_ |
.--- -| / / _| / \\ | _/ |- ---.
| |______________/_______________\ \\_________| |______| |
| [3m \\Ă·eĂ· [0m________| |
| /______________\ |
| _________ |
| _____________ ___________ _______|_ / |
| ___\____ / \ / | |
`--------- -| _/ _/_ | \ _/\ |- --------------'
|______\ /_____________/______________|
\ /
\ / sTAFF:
\ /
\/ SHADOWER,AUTOPSY,EXOCET,
LINEBACKER,FURY,NIGHT ASSASSIN


HOODLUM WHQ! · DELIRIUM WHQ! · ARCLITE WHQ! · SNEAKERS WHQ!

DIGITAL CORRUPTION USHQ! · LIGHTFORCE USHQ! · NUT&BOLT WHQ!


·SINCE 1992·

@BEGIN_FILE_ID.DIZ********************************************

PASSWORDS FROM AMIGA USERS WORLDWIDE
SCORED BY USING HOLGER KRUSES OWN
KNOWN AND WELL TALKED ABOUT BACKDOOR
IN MIAMI TCP STACK...CAN HE STILL DENY
IT AFTER THIS??? FUCK YOU HOLGER KRUSE!

********************************************
@END_FILE_ID.DIZ


SOME FUCKING LOGS AND PASSWORDS MIGHT BE INVALID BECAUSE THIS LIST HAS
BEEN AROUND FOR SOME TIME AND HAS BEEN USED ON OCCASION!

IS YOURS ON HERE??? :-)

HOLGWHORE KRUDE - REMEMBER THE NAME BECAUSE I HAVE JUST STARTED ON MY
REIGN OF H/P/A/V ON THE MIGHTY AMIGA!


USERNAME IP/ISP

00503201 ip405.nordwest.net
0600e142 194.243.31.199
0avolta Pescara4-3.tin.it
100111,463 md19-090.mun.compuse
105 ppp002-mur.ibbs.ch
120005104000 ppp73.hil.tele.dk
120007958000 ppp313.arh.tele.dk
120015000171 ppp4.had.tele.dk
2736993000 WP01PORT15.highway.teleko
3698138 ppp-33.a2points.com
4wd dialin-a2-10.Melbourne.interNex.net.au
6118 port122.koeln.ndh.net
71006233 ppp18.mdlink.de
72016,1237 lon-dial-59.compuserve
950947 pcwse147.umh.ac.be
a.steuber pC19F5428.dip.t-online.de
a00010036 t3o14p21.telia.com
a00091237 t1o8p39.telia.com
a00315650 t8o28p44.telia.com
a010023509 t8o30p19.telia.com
a04276 fi02-ts2-05.pn.itnet.it
a1004 dialup2-39.itv.se
a1a97769 nlsn01m01-40.bctel.ca
a4000 dial03.prz.tu-berlin.de
aaa432 ppp0260.tcom.co.uk
abattil Parma4-26.tin.it
abbys dc2-modem40.dial.xs4all.nl
ablock h103.stud.uni-hannover.de
actarus cis-eik-m02.eikonos.it
actionhq dls019.ikp.pl
acwzorek dial-20.dialup.medianet.pl
aevers toulouse2-36.hol.fr
againt poort44-ip-x2.enertel.cybercomm
airwin ppp273.enterprise.net
akira dial08.eli.net
alald USR-Paris-38.easynet.fr
alb max-dijon.isdnet.net
alckojjg ts4.zrz.TU-Berlin.DE
alden1 airmail.net
alexiii cl-4.ELIA.Eu.Com
alinewt dip-195-74-66-70.thenet.co.u
allanm dialup-39.mackay.net.au
alley du-1003.claranet.co.uk
allinone du47-99.ppp.algonet.se
alronche a-co6-61.tin.it
amazze a-rm20-58.tin.it
amethyst ppp10.NAS2.dotstar.net
amigat DialIN22.vr.in-berlin.de
amigo lineI2.ping.de
andreas.just port37.sz-online.de
andres.maschtaler port-55.ob.kamp.d
apagnott metz2-10.hol.fr
apedretti/PPP 194.243.194.249
apetit ppp11.alpha-c.net
apex isdn060.stuttgart.netsurf.de
apreston mth09.k2nesoft.com
Ardellb@PPP ts001d12.bat-la.concentric
areisc isdn17.rz.fh-aalen.de
aren3422 lie0.euronet.be
argus netppp-025.wuerzburg.dialin.ma
arminb ppp08.ludwigsburg.netsurf.de
arno.r dialin8.woergl.netwing.at
arnold 208.8.184.102
arnor arnor.demon.co.uk
art nhj.nlc.net.au
Arto Huusko dialup-vsa041.qnet.fi
asny0003 ip181089.student.gu.se
atdur79 dps25-02-p07.kn.saix.net
atila ppp3.bozic.co.yu
atze ppp86.rhwd.owl.de
Avatar Avatar.warstein.owl.de
avillett a-fi7-32.tin.it
b.krummenacher lss17pub129.bluewin.c
baerchis baerchis.dialup.fu-berlin.d
balocco ppp-132.aix.pacwan.net
Bandit dialup24.inpw.net
barthur duppp3.chm1.franklin.pa.net
basic.klun ppp-padova76-237.iol.it
bastard pppha13.czcom.cz
bastian ftmfl1-97.gate.net
bdi1028 msx-04-1-29.1033.cybercity.
be012252 pool02a-194-7-46-119.uunet.
beatnik anonymous231.ppp.cs.tu-berli
beckers ppp26.dialin.tu-cottbus.de
bellu ppp-209017.dial.netppl.fi
ben foobar.co.uk
benc socrates.qatraining.com
bentoh ti01a22-0125.dialup.online.no
Bernd.Uwe.Rehlinger deck-184.frankfu
bg000111 ppp47-bz.dnet.it
bhofmann dialin50.aschaffenburg.nets
bigbus bigbus.demon.co.uk
biis biis.demon.co.uk
billhar oak-port979.jps.net
bobdavis modem45.cadvantage.com
bodger e1c13p39.scotland.net
Bolle gate04.dialin.ulm.de
breising ppp43.pm3-1.peoria.ocslink.
broline ang60.pp.dlc.fi
brownson lipan-ppp008.lipan.net
bth q109.din.cuci.nl
buck buck.prima.de
bunchofgrapes bunchofgrapes.demon.co
butch ppp04.geelong.austasia.net
c.runda dialin306.xpoint.at
c73019 ascent2-10.uni-paderborn.de
ca,ppp,av333 trt-on12-43.netcom.c
Carsten.Stach port5-dn.soco.net
castel61584 dialin483.freeaccess.nl
cavasino ts6.cuc.unipa.it
cba 194.250.111.57
cbowling remote485.compusmart.
cdawson ppp38v1.mtx.net.au
cherubel ppp-107-69.villette.club-in
chewy chewy.prima.de
chrysiko ppp-mar241.ath.forthnet.gr
clabul dp32g.cobweb.nl
clamon mo1-as-ppp010.ats.it
claus async1.mediatec.it
claush port26.pin-net.de
clay.ppp sac16-173.calweb.com
cloudbase2 cloudbase2.demon.co.uk
clubint/artisslc 195.36.143.166
clubint/bkd annecy4-3.club-internet.
clubint/bpresles PowerAmiga
clubint/d_neveu rouen7-7.club-intern
clubint/jpm1503 mans2-198.club-inter
clubint/jsr nancy3-132.club-internet
clubint/mouloud 195.36.147.4
clubint/nico_c bordeaux8-37.club-int
clubint/pertin annecy3-105.club-inte
clubint/petita toulouse11-122.club-i
clubint/rdx nancy5-101.club-internet
clubint/sellim orleans6-36.club-inte
clubint/speedy mulhouse5-71.club-int
clubint/stfm cergy7-3.club-internet.
cmb1 t1o63p256.telia.com
co0432 dialin-19.coburg.baynet.de
cochrane zhwbs-E1-07.limmat.ch
coffeeshop coffeeshop.demon.co.uk
colargol user160-bxl.online.be
contact duna-9.dialin.datanet.hu
crapston crapston.demon.co.uk
csollet ppp-rack217.melun.cci.fr
cura3642 user119-bxl.online.be
cyriheck cs3-ppp16.euregio.net
d00033445 t4o101p15.telia.com
d0012501 ip171.nordwest.net
d95...@nada.kth.se 10.0.2.15
DALONSO@teleline1 rad011089.radius.te
danv pm5-s1.colba.net
darcyb Kirkland-PM.nt.net
DAREKC modem152.gronet.pl
dargaard dargaard.demon.co.uk
darknite warp.hb.vossnet.de
def ts3-07.vcr.istar.ca
degs dialin18.oshawa.globalserve.net
dekemp p173.coos2.harborside.com
desrat txmia5-34.gate.net
devil hs1-153.handshake.de
dfischer baw8pub208.bluewin.ch
diaifid1 dadovago1123.dada.it
disaak chk3d3.dial.uniserve.ca
dko10197 msx-06-1-12.1033.cybercit
dko12001 msx-0b-2-1.1033.cybercity
dliddlea dyna22-08.compulink.co.uk
domi ppp10.canl.nc
dragon acceso-24.madrid.idecnet.com
drizzt drow.nasa.gov
dsoccoli ppp14.ts.spin.it
dtalmud client-151-200-125-42.bellat
dvukovi2 ac30-p10-zg.tel.hr
dwish alkmr1-p129.worldonline.nl
dzerbone Genova7-63.tin.it
e27230 ascent2-16.uni-paderborn.de
eastier lyon2-33.hol.fr
ebbakker vnlo1-p17.worldonline.nl
edimatte a-ch3-10.tin.it
edwardss ppp33.morris.rural.escape.c
ee97228 gothmog.esoterica.pt
egasc kip-43.hol.fr
eger NCC-1701D-10.xtra-net.de
ehr tty069.softdisk.com
ELN/jonmines ip178.seattle11.wa.pub
ELN/palacio pool002-max12.mpop2-ca-us
elyograg ppp-207-214-186-95.anhm01.pa
emilio 195.103.137.30
emma0004 ip181081.student.gu.se
erikvp.ppp pm3-139.spots.ab.ca
esojanen.ppp dynamic44.dialup.jy
essepi.time ppp-torino70-189.iol.it
etoilep portve09.worldcom.ch
etstephan stephan.et.tudelft.nl
EugenAlbiker wolf22.swol.de
f9296377 dip115.f2.pools.rhein-main.ne
fabmigl a-pd11-45.tin.it
fam.jerner 194.198.202.227
faustin ppp-bolzano81-116.iol.it
favers ppp27.a13.execulink.com
favers2 nnt-141.oxford.net
fdhollander port2-48.nordnet.fr
fedepo mi-line-017.comm2000.it
ferlucch a-mi18-8.tin.it
finlaym fastlink38.fastlink.com.au
fliepilz mm-ppp78.primus.baynet.de
flipper ts1.f1304.quebectel.com
flomasc c-rm10-196.tin.it
fn037707 ip001.pool-430.flashnet.it
foul 195.6.208.70
fpvi...@flashnet.it ip005.pool-33.fl
frallan p31.one.canit.se
frogd022 dyn-10.lyn.oleane.com
fromg131 dyn-31.dij.oleane.com
fruthe ppp388.ts.rz.tu-bs.de
fsepulve-ip remote-acc-35.unil.ch
fst dial-pri-na035.active.ch
fti/AH9AZde wanadoo.fr
fti/dpYtRgF ren3-235.abo.wanadoo.fr
fti/e7gqyd4 avi2-194.abo.wanadoo.fr
fti/ed2cb6h rou5-168.abo.wanadoo.fr
fti/KERd2bN bes1-94.abo.wanadoo.fr
fti/vhWCdvU mpl2-13.abo.wanadoo.fr
fti/WNZertd 193.252.200.153
fti/XTNugKa 193.252.149.149
fuerst fuerst.ms.tlk.com
gae baw8pub181.bluewin.ch
gallo du-02.concert.it
garryd eck.net.au
gast dc2-modem1573.dial.xs4all.nl
gclutterbuck dialin3-30.ndirect.co.uk
gdonner OCPM2-2-16.cyberlink.com
geller pC19F77B3.dip.t-online.de
Georg.Rottlaender port13.bn.ivm.de
gerfiaux ne1-a10.mcnet.ch
germano ppp-1.interlandsrl.it
giguere1 ppp-110-31.villette.club-in
giromcl bar-bga6-A50.rhone.ch
girondid club-internet.fr
girvan girvan.demon.co.uk
gjc ns1p8.cht.perigee.net
gjest a12...@online.no
gk1051 pm2-69.hrz.uni-giessen.de
goande du185-248.ppp.algonet.se
gogoncea cl-1.ELIA.Eu.Com
gora du86-153.ppp.algonet.se
gorswill p53-max32.auck.ihug.co.nz
gowest hb49.hb.vossnet.de
griffware p67.nas1.is4.u-net.net
grog ppp43-39.hrz.uni-bielefeld.de
grommet modem40.coffs.key.net.au
groshart ppp10.nfinity.com
grustico 208.160.145.100
grval port53.ath3.tc.hol.gr
GTE/gwt 1Cust169.tnt1.elizabethtown.k
guest asn14-243.mcmail.com
gwagnsso 193.216.116.4
gwormus ftc-0109.ppp.frii.com
h.muhl pm.NMS.CLS.NET
habbeton line-133-37.dial.matav.net
hahof ppp-mab124.freiepresse.de
hajo telco082.comcity.de
halunde 193.216.37.76
hammiche wn17-059.paris.worldnet.fr
hanlonja rhsyts11c44.nbnet.nb.ca
hatter.ppp sac13-203.calweb.com
haviru 205.177.20.107
headwind mbv2-pl-ri29.kos.net
hekr ti34a08-0044.dialup.online.no
helix ac13.tel.hr
henrp orkan.sk.sympatico.ca
herold plzD001.pvt.net
hines_j iolinc.net
ho1196 194.95.215.129
horechuk ppp-161.am1.barint.on.ca
hosty hosty.demon.co.uk
hpresser mm-ppp84.primus.baynet.de
hsutodek debrec-10.dialin.datanet.hu
hunter d3-eger.elender.hu
hvymetal p106.nas1.is5.u-net.net
hweight reggae-07.iinet.net.au
hyrax nexus.fl.net.au
i.younas p30-dunlin-gui.tch.virgin
iainb dip-195-74-66-69.thenet.co.uk
icampbell p28-m8-wn4.dialup.xtra.co.
ideal 194.247.206.61
ignamelo ignamelo.rivarolo.alpcom.it
igracki 195.99.200.2
iksmas-borg green.pomac.com
im007 oak-port1599.jps.net
inab 147.91.1.5
Indy 195.52.230.122
inf-deble par20.info.isdnet.fre.com
Infobahn p405275.DO.dip.t-online.de
infovia if-216.arrakis.es
internet deinet cazeneu slip139-92-3
internet-signup modem116.scully.kingst
internet.usinet.rcurti1 slip139-92-8-
IPSER9 ADV49299 internet
isspbrno isspbrno.dial-up.cz
itr ppp001.clari.net.au
ivani du48-151.ppp.algonet.se
iw0005 195.191.39.102
jabbour BGSZ29.kfunigraz.ac.at
jack tc01-21.alfaskop.net
javierdlr@redestb ppp123.207.redest
jcallus engine24p5.maltanet.net
jd591879 slirp.linux.tc3net.com
jdlrobb p16-tnt-ak-1.auck.ihug.co.nz
jeffharv c6-p46.senet.com.au
jejn a216.dial.kiruna.se
jens.grundmann pC19F5B7D.dip.t-online.
jfossbak mp-213-33.daxnet.no
jgerman wizpal.paonline.com
jgirvan 120-sx-wpg.ilos.net
jhk pm22-22.image.dk
jignasi pppAA.adam.es
jklingele line10-loerrach.datacomm.ch
jkruege RAS0206.UNI-MUENSTER.DE
jlsc00346 usr205-edi.cableinet.co.uk
jmarcet@redestb ppp169.201.redestb.e
jmorata@kaos nas48.modems.kaos.es
joek slip107.wcos.com
joemck joemck.demon.co.uk
joerren uni-muenster.de
joke line17.ping.de
jonte ip-167.salghugget.uddevalla.se
jooon tc01-17.alfaskop.net
jpereira annecy3-99.club-internet.fr
jpesek ppp37-5.hrz.uni-bielefeld.de
jreyes acceso-16.tenerife.idecnet.co
juanmweh dial-pri-zu206.active.ch
juergen.vossen surfk166.koeln.n
juni i74p140.pp.dlc.fi
justin d1-s155-185-telehouse.mistral.co
jwoods trj65.travel-net.com
kalk du93-250.ppp.algonet.se
karomel p16-term1-mun.netdirect.net
kartel max17.ihug.co.nz
kberg du2-3.ppp.algonet.se
kenwyn kenwyn.demon.co.uk
khartman lan-vis2-16.cancom.net
kierene modem118-per-isp-2.one.net.a
kily kily.ruhr.de
kim dial015.titan.fi
kimme ppp-5.arcticnet.no
kimmov ppp-209026.dial.netppl.fi
kitchens 208-236-19-200.wtd.net
kjemoerk ti01a06-0053.dialup.online.
kjust ppp-120.arco.de
klundl pm22-40.image.dk
kokatou pm2-s21.colba.net
kraewinkels itx01034.litx.net
krille blackbird.df.lth.se
kscullyp asn126.whidbey.net
ksoze azts2-104.aznet.net
kstengel maxi12.nuernberg.netsurf.de
kstrauser dm-38.pcis.net
kunzmann warp11.gi.eulink.de
l-karls du137-150.ppp.algonet.se
lammacl ame1-cs-16.win.bright.net
larit t007.pp.utanet.fi
lawman p36.nas1.is3.u-net.net
lear du103-93.ppp.algonet.se
leinwebj dialin8.asam.baynet.de
leu03246 pec-13.au1.ef.uunet.de
levas ppp-nic92.logos.cy.net
lgomez pppA6.adam.es
LiberatoR pm3-3-15.stratos.net
lic711r du169-244.ppp.algonet.se
limmer line19.inode.at
linus bay2.icenet.fi
littleed pppK13007.francenet.fr
llongone LAquila4-47.tin.it
lordart usol-new-nj-031.uscom.com
loumi reggae-09-6.nv.iinet.net.au
lpiston Firenze9-63.tin.it
luciadif a-mi33-59.tin.it
lurch 194.106.165.1
m.rustia host-png-ibs078.pronet.it
m.ventura lon4-12.ukonline.co.uk
m00mqs00 asn17-133.mcmail.com
machi rdutlp14a2.impsat.net.ar
madjack1 hki-dk5260-1-59.kolumbus.fi
madscientist madscientist.demon.co.uk
mafutha@ppp ts001d01.lan-pa.concentric.n
maik.daum+wi isdn17.rz.tu-ilmenau.de
manni.ap pC19F8E61.dip.t-online.de
marini.m sanbocisco-14.mbservice.it
mark.buonfrate surfk95.koeln.ne
martin.eriksson z250111.2.sbbs.se
Martin.Rottlaender port10.bn.ivm.de
MartinSprenger rott6.swol.de
mash mash.prima.de
masiri portc15.async.csuohio.edu
masone@databasedm 194.224.19.127
matrx line-192-28.dial.matav.net
matsolov.rustad z25020.2.sbbs.se
mattbr modem15-pen-isp-1.one.net.au
matthew kudos-34-151.kudos.net
maxime 151.99.135.19
maxx 10.0.2.15
mbarte2 RAS019.Stud.Uni-Goettingen.de
mbelle ppp127.nor.com.au
mcfrank med01.mediatel.it
mcmxc p-sale12.hydranet.it
mcsn slip3.univr.it
MD4690 net130-235.mclink.it
ME3886 net128-100.mclink.it
ME7436 net128-089.mclink.it
medial ac10-p15-zg.tel.hr
medway abel-167.abel.co.uk
meier dial-esb08.bayreuth-online.de
mesamoo cust15.max7.seattle-k56.aa.net
metohija P-198.101.EUnet.yu
mfehrmann 195.145.139.32
mha-pens mha-pens.demon.co.uk
michael.doerr pm-hd2-024.Heidelberg.n
michael.preuss port-16.ca.kamp.de
micks-cupboard micks-cupboard.demon.
micro053 ppp10.cybernet.it
midyette lpm3bs29.intrstar.net
mik 195.66.162.147
mikalgu ppp-1.molde-1.globalone.no
mike-fulton dip-195-74-66-90.thenet.co
mikez wches104-pri.voicenet.com
milsaas ti01a10-0044.dialup.online.n
mjfuller 209.54.157.66
mlf dial-18.fokus.gmd.de
mliukka nym91.pp.dlc.fi
mmaier4 pC19EBC07.dip.t-online.de
mmerkel portmaster1.rz.uni-mannheim.de
mnurmin hki-dk5260-3-178.kolumbus.fi
mobilis brkfl3-107.gate.net
mom4 wormhole3.sunflower.org
mossujma 195.114.64.193
mpfauder@netspain 195-57-247-183.usr
mrclean 206.68.76.8
ms041191 user-38ld0mk.dialup.mindspr
ms172461 user-38lc87k.dialup.mindspr
ms300788 ip241.york.pa.pub-ip.psi.net
ms406966 user-38ld8vi.dialup.mindspr
msawyer netcom8.netcom.com
msch strasbourg2-21.hol.fr
mstodola ppp05-51.ght.iadfw.net
mtc hip4a.grolier.fr
mugulo@arrakis ic-160.arrakis.es
musicsvs ppp-asft01--026.sirius.net
mwyatt lon55.kih.net
n1jvfg46 hlfx49.mtt.net
n210014209 t8o206p47.telia.com
n210015495 t4o203p48.telia.com
n210019879 t1o202p33.telia.com
n210030896 t2o207p3.telia.com
n6067257 black0.ncl.ac.uk
name istar.ca
ncappelli creek.cld.it
ncat ppp28.tmis.net
nevh max04-181.enterprise.net
nfn08040 p05.pm2.naples.net
nfrancfo portge47.worldcom.ch
ngotsis ppp110.ath-users.acropolis.ne
Nh.hayn ppp61-as1.flensburg.netsurf.
niceone usr1ppp12.fiastl.net
nofear nofear.demon.nl
norman ppp041-nov.ibbs.ch
np02pi lisas1-tp.telepac.net
np03vh alv3-p3.telepac.pt
ns1064jm pan-ppp003.passau.netsurf.d
nuearth nuearth.demon.co.uk
nugteren FAC01P20.tref.nl
nyga Dialup-1.miko.pila.pl
nzanzi a-ra6-3.tin.it
odn05523 dialin1034.odn.net
oetienne strasbourg-46.hol.fr
ogisha 147.91.1.5
ogugg mtl1-59.netrover.com
ohp942r du1-234.his.tninet.se
olapet p1c1a5.intron.net
olho MCCXLII.dyn.sci.fi
olicorp portfr11.worldcom.ch
oliverr max05-005.enterprise.net
olli dialup9.hdk-berlin.de
ollip jkyla-dk5260-1-158.kolumbus.fi
ologram ppp04.agarde.it
oms CMLX.dyn.sci.fi
orlor ct-hartford-us1632.javanet.com
ortonwistow ortonwistow.demon.co.uk
oshuella m104.bookmark.com
ottemann node12.dial.Uni-Magdeburg.D
P1186 starbase.inka.de
p4u00590 dialup016.mons.eunet.be
palace p43.nas1.is2.u-net.net
Parega n246-89.berlin.snafu.de
Paris harconia-2.ts.mke.execpc.com
partsi CCCXLVII.dyn.sci.fi
Patomic atomic.bb.bawue.de
paubert portge83.worldcom.ch
Pb84021 ns1135.ber.netsurf.de
pbeyond ppp1.hb.north.de
Pbogi ppp00.sylaba.poznan.pl
PCCONTACT phaD003.pvt.net
Pdelfino hlm-isdn01-05.dial.xs4all.n
pdenomy pool78.greynet.net
Pdepot1 pm1.bawue.de
pdevilla limoges-10.hol.fr
pdiped Matera3-77.tin.it
Pdrider ip-20-118.phx.primenet.com
peps006 ADV47514 INTERNET slip139-92-3
perwilhe ti28a02-0013.dialup.onlin
Pfb5y037 max1-247.public.uni-hambur
pfbussma router-analog.peine.netsurf.d
Pfe5y021 max1-099.public.uni-hambur
pfitzp port60.readynet.net
Pfk5a001 max1-249.public.uni-hamburg.
phantasy p125.nas1.is3.u-net.net
Phoeba dc2-modem1291.dial.xs4all.nl
phogan dialup-010.wexford.iol.ie
Phoudini dc2-modem1444.dial.xs4all.nl
Phpschd ip93-12.tor.interlog.com
pierluil a-ca7-20.tin.it
pierop ts1110.gpnet.it
pin00953 idialup107.brussels2.eunet.
pin08928 idialup105.brussels2.eunet.b
pin10568 dialup017.mons.eunet.be
piro pp184.95net.com
pisle pisle.u-net.com
Pjarno as5200-00.kcbbs.gen.nz
Pka82011 ns.karlsruhe.netsurf.de
Pkernal 194.42.72.174
Pkipster ip177.pom.primenet.com
Pkleberg n245-107.berlin.snafu.de
Pkrumrey n245-79.berlin.snafu.de
Plabine ip-58-147.sbd.primenet.com
playboy pm10-60.image.dk
pl...@dial-mich.net pm144-02.dialip.mi
pmarquess pm2-85.dial-IP.EmpireNet.n
Pmlemke n31-81.berlin.snafu.de
pmmikee mmikee.cts.com
Pmoppel moppel.oche.de
pohling 193.174.103.238
porridge du206-4.ppp.algonet.se
pp2165 ppp196.mes.pssr.ru
ppgrob grobi.sax.de
ppozzi ppp-3.nw.ru
ppp 122.122.54.10
ppp,rock dialup-06-46.netcomuk.co.uk
ppp267988 207.net7.nauticom.net
PPP:ciro scognamiglio bbs-10.galactica
PPP:Whistler 208.192.113.116
pppeter 8-155.dialup.surnet.ru
Pprodigy ppp5-phx-186.futureone.com
Ppsychic psychic.ruhr.de
Pr.b n221-83.hh.snafu.de
Pred dslip05.canit.se
Prene.wunderlich n163-107.berlin.snaf
Prepoman pool3-019.wwa.com
Prfish ip-23-052.phx.primenet.com
promptus promptus.demon.co.uk
protech ftc-0406.ppp.frii.com
psolar ozemail.com.au
Psponsfor ip60-203.cap.primenet.com
Ptermi termi.in-berlin.de
Ptgl n242-117.berlin.snafu.de
ptknabe ttyC3.helmstedt.netsurf.de
Ptomsmart1 dialin28.kus.kiss.de
Ptroll f35678.all.de
ptukiain hki-dk5260-1-26.kolumbus.fi
pvanes nmgn1-p28.worldonline.nl
Pzvdrops zvdrops.aball.de
p_molinari molinari.xnet.co
q26781 ascend1-25.uni-paderborn.de
radata ti01a01-0058.dialup.online.no
radojevd ts18ip148.cadvision.com
Ralf.Lillemaee dialin24.detmold.netsu
rcarletti 194.184.19.194
rdm ppp-milano67-55.iol.it
redhorn redhorn.demon.co.uk
redtower dip-195-74-66-85.thenet.co.uk
regl dyn58.island.net
relliott ip247.ts4.dialup.ottawa.cybe
renemob p94.zeelandnet.nl
rexel DCXLIV.dyn.sci.fi
richard ppp4-232.geneva-link.ch
richardh Salerno4-52.tin.it
richi gatebe3-24.access.ch
rickilak du171-97.ppp.algonet.se
rigger ppp-134.customcpu.com
ripperj mi3-max.infostrada.it
rjoppe ppp80.st-cath.niagara.net
rknight ppp214.st-cath.niagara.net
rm03330t ip010.pool-04.flashnet.it
robg ppp29.zweitehand.de
Rob...@vossnet.de u-109.rostock.ipdi
rogue ts1-02.boi.cyberhighway.net
rohaagen ti29a34-0005.dialup.online.n
rolf rnis95.telmat-net.fr
rolf1 ip51-176.introweb.nl
romontic 194.184.21.52
roosendaal roosendaal.demon.nl
rosso ppp-208.aurec.avo.fr
rp13076 as10-pri39.rp-plus.de
rplutchak 207.67.107.2
rpuffer dialin19.edm.oanet.com
rschnick mtplsnt38.lisco.net
rsitch ludyn1-7.lakeheadu.ca
rst ts20l10.pathcom.com
rthomson dialup32.ednet.co.uk
rubico dc2-modem1316.dial.xs4all.nl
rudecow rudecow.demon.co.uk
ruesike ascend.dialup.uni-potsdam.de
rufus p017.alk.euronet.nl
russell Modem21.wts.com.au
rvs 194.235.116.252
s-123891 p126-12.ppp.get2net.dk
s-18033 dialup235-3-34.swipnet.se
s-213169 dialup111-11-1.swipnet.se
s-233193 dialup163-1-4.swipnet.se
s-240818 dialup238-1-8.swipnet.se
s-281665 dialup84-1-15.swipnet.se
s-30612 dialup206-2-33.swipnet.se
s-318772 130.244.149.83
s-321329 dialup103-2-24.swipnet.se
s-336647 ldosdialup181-2-4.swipnet.
s-342223 dialup106-1-5.swipnet.se
s-4126 dialup238-2-50.swipnet.se
s-505146 tele2.c2i.net
s-53610 dialup152-2-44.swipnet.se
s-55336 dialup92-1-33.swipnet.se
s-55885 dialup186-1-38.swipnet.se
s-60182 dialup85-4-3.swipnet.se
s-68011 dialup147-1-34.swipnet.se
s-70882 dialup109-10-15.swipnet.se
s-79487 dialup168-4-44.swipnet.se
s-83766 mail.lysator.liu.se
s8916314 ib041.extern.kun.nl
s92808 wex131.extern.uni-wuerzburg.d
sam.max@arrakis if-41.arrakis.es
sammyli ldn1-p208.worldonline.n
samwel du122-149.ppp.algonet.se
samymax 212.55.8.132
sangold mg128-244.ricochet.net
sbrajkov ac49.tel.hr
sc0171 ascend18.extern.uni-essen.de
schreiber2 dip180-2.hamburg.netsur
scooby dip-195-74-66-68.thenet.co.uk
Sdeutsch nac25.graz.austronet.at
sdomina glo-r1a-12.cybertrails.com
seed p12.sharon2.actcom.co.il
serg slip139-92-34-246.mos.ru.ibm.ne
servisce ac14.tel.hr
sgiambo raf25.ethz.ch
shk shk.pp.sci.fi
shuttle p14.bs.shuttle.de
Shyper eunet.yu
silfe Torino9-53.tin.it
silhavy zcu-cs-asy1.zcu.cz
silv ip116208.keycomm.it
simonlon ppp304.enterprise.net
skipper skipper.prima.de
skuba tuctc7-109.flash.net
sky53634 dialup5.waremme.skynet.be
sky79703 dialup107.herentals.skynet.b
sky80273 dialup18.namur.skynet.be
sky85757 dialup44.nivelles.skynet.be
sluis172 hrvn1-p12.worldonline.nl
smarko pma-031.wwnet.fi
smartin@kaos nas47.modems.kaos.es
smartu Roma32-253.tin.it
smiler smiler.demon.co.uk
SMOKY 102227,1254 ad63-254.arl.compus
snowman primux01-06.north.de
soguhe as7.dialin.hs-wismar.de
sonno ppp-105-12.villette.club-inter
SP170467 host-pf-191.seitz.net
spab1625 mp1-c84-p129.span.ch
spalnq du46-7.ppp.algonet.se
spAnton dialhost14.atlant.ru
spook Darren @ComACom.com.au
SPRY06,SPRY734846 hd81-044.hil.compu
SPRY137258 hd60-068.hil.compuserve.c
srueeg1 dialin-muensingen-5.spectraweb
st617636@accesosis ppp3136.interbook
starblaz du45.blo.ptd.net
steigerw NAFp2-067.rz.uni-frankfurt
stevesdt ppp-milano66-253.iol.it
stilian pppa2.grecian.net
strange p110-32.ppp.get2net.dk
string etno.nvm.co.yu
st_login port7.the4.ppp.hol.gr
su0140 stud-145.HRZ.Uni-Dortmund.DE
sullr farman17.sk.sympatico.ca
svitek ppp-41.arco.de
swest th-pm00-34.ndirect.co.uk
swmpthng pm9-183.his.com
synchro pppBB.adam.es
sz0931 maxi37.nuernberg.netsurf.de
szymczak ppp-151.m2-1.wsr.ican.net
T9371000 dyna-azh-10.dial.eunet.ch
tapaz 194.177.107.136
tbeatty line338.ebtech.net
tbrandt tbrandt.dialup.fu-berlin.de
tcm host-193.reutlingen.netsurf.de
tcripe dialup01-204.metalink.net
tdjuan gcdialup23.dataline.net.au
tebbesen 193.216.37.175
technomage xcom7.xpres.net
tha-rik@riksnett t5o207p8.telia.com
the-dungeons the-dungeons.demon.co.uk
thecremlin thecremlin.demon.co.uk
thinz ppp-43.arco.de
Thomas.Wulff dialin1.detmold.netsurf.
ThomasKoerner blum1.swol.de
ThomasLorenz freu23.swol.de
thotti inq151.pp.dlc.fi
thover ip176.usr6.usw.du.nwlink.com
tj srv-17.roc.ny.frontiernet.net
tjung dial15.trionet.de
tjuslin CDXC.hdyn.sci.fi
tldaley ade1-33.wantree.com.au
tomg modem2.kaszub.top.pl
tonic dialup177-2-23.swipnet.se
torchia cisco104.windsor.igs.net
tpinfo ip139.seattle9.wa.pub-ip.psi
traversy 205.233.146.2
ttavoly amiga.cistron.nl
tumu ppp-209080.dial.netppl.fi
tundrah kou20.pp.dlc.fi
turk ascend5.gulftel.com
turnermator lon6-59.ukonline.co.uk
tweniger remote8.gc.incentre.net
twentyfour twentyfour.demon.co.uk
tyoung ott1-44.netrover.com
u.b...@okay.net ip11.berlin.okay.n
u33100682 t6o37p43.telia.com
u83902212 t3o28p40.telia.com
ud311an pC19F6EC0.dip.t-online.de
uda FM goodnet.com
uk lon2-49.ukonline.co.uk
uk,ppp,ami netsrv02.netcom.net.uk
uk,ppp,dem1 dialup-17-13.netcomuk.co.uk
UK/solaaq53 userj322.uk.uudial.com
UK/solpz23 MrMitch_Amiga
usu62@infocanarias dialup33-107.infoca
vega cs-bologna-1.queen.it
veliki ppp1.bozic.co.yu
verohans dial1.itn.cl
videza55 klu_as14.carinthia.co.at
vol/jwillis ip29.washington11.dc.pub-
voytek pm1s09.lanline.com
waldiasp p30-max18.akl.ihug.co.nz
werecat 209.20.141.35
whittaker whittaker.demon.co.uk
wideon wideon.demon.co.uk
wkrause hb142.hb.vossnet.de
wonko du70-25.ppp.algonet.se
wpierre ppp41.netgazer.net
wsilvera wnpgas01-p56.mts.net
wwt5491 ppp-04-3-04.dialip.rit
wzm735l du160-0.ppp.algonet.se
xa00054 ip056.pool-17.flashnet.it
y0000431 ppp343.ts.rz.tu-bs.de
y0004083 rznmax.rz.tu-bs.de
ychatene paris3-19.hol.fr
yoda popclient05.stadsnet-rdam.nl
yserra ppp-115-245.villette.club-int
yu173942 curly02.slip.yorku.ca
zapek mail.deckpoint.ch
zebulon d-ma-superpop-163.ici.net
zerocom n247-118.berlin.snafu.de
ziggy ppp203.enterprise.net
zsuboti1 ac13.tel.hr


[@@@ Part 2]

@BEGIN_FILE_ID.DIZ********************************************

YET !MORE! PASSWORDS FROM AMIGA USERS
SCORED BY USING HOLGER KRUSES MIAMI
BACKDOOR. I WONT STOP UNTIL HOLGER
ADMITS WHAT EVERYONE KNOWS, THAT HIS
TCP STACK HAS HOLES LIKE THE GRAND
CANYON! ...CAN HE !STILL! DENY IT AFTER
THIS??? (PROBABLY) FUCK YOU HOLGER KRUSE!

********************************************
@END_FILE_ID.DIZ


OK OK SO PEOPLE ARE TELLING ME AND TALKING AND SAYING THAT THE
BASTARD IS STILL IN PUBLIC DENIAL! WELL MR.FUCKING KRUSE LETS
JUST KEEP THEM ROLLING OUT UNTIL YOU FINALLY CRACK UNDER THE
USERS PRESSURE AND TELL ALL WHAT THE FUCK YOU HAVE BEEN CODING
INTO MIAMI!

SO LETS GO WITH ROUND 2 OF CELEBRITY BACKDOOR! ARE YOU ON HERE
MAYBE? WATCH AS THE PASSWORD LISTS BUILD INTO A BIG COLLECTABLE
WHOS WHO OF AMIGA LIBRARY RIGHT BEFORE YOUR EYES CARE OF HOLGER
KRUSE!

HOLGWHORE KRUDE - REMEMBER THE NAME BECAUSE I HAVE JUST STARTED ON MY
REIGN OF H/P/A/V ON THE MIGHTY AMIGA!

USERNAME ISP

#kwilde ali-ca14-05.ix.netcom.com
00000350216604068910990#0001 p3E9C2060.dip.t-online.de
0000146133190934365799#0001 pC19F307
000028088527320064441496#0001 pC19F4
000091995460061523548#0001 p3E9C374C.dip.t-online.de
0001141675050211499454#0001 pC19F32E3.dip.t-online.de
00011765726404072370014#0001 pC19F7A
00013318752403455221967#0001 p3E9D4A
00016608883503920461232#0001 pC19F16
000168853899049531751#0001 pC19F467A
0001985413910309936369#0001 pC19EA17
00020047969203976203520#001 pC19EA680
0002575563350307231377#0001 pC19F67C
00032846004703413384694#0001 pC19F9B
00032861683302362208257#0001 pC19F99
00033677458203412326414#1 pC19F5B1E.dip.t-online.de
00033677458203412326414#3 pC19F9B35.dip
000353120315068435388#0001 pC19F08EA
00036083662003817954790#0002 pC19F14
0004011724203200221464690001 pC19EB510.dip.t-online.de
0004453723440304565047#0001 pC19F648
000551115490 pC19F43D9.dip.t-online.de
00055561849403532231789#001 pC19EA54
000613611040046428488#1 MooNFreaK@t-...
00075214175503817681273#0001 pC19F14
0008095023510387449922#0001 pC19F925
0008162020240797123597#0001 pC19F254
00082621707002152516790#0001 pC19F54
00082809699903373114708#0001 pC19F64
0008615435640292131032#1 pC19F572A.dip.t-online.de
101,249949 194.95.192.173
110371,2123 sfr-qbu.compuserv
114231,3373 ld32-142.lon.compus
114321,601 compuserv
114325,1053 hil-compuserv
120010353409 ip38.odnxr1.ras.tele.dk
124832008911 ppp20.hj.tele.dk
50972 ppp25-fl.cruise.de
5LE lfleming lfleming.actrix.gen.nz
6275 port122.koeln.ndh.net
abreg rennes-14.hol.fr
aIRwORX dialup71.b.vossnet.de
akendal host-209-214-140-41.dab.bell
alen linea5.gattinara.alpcom.it
alexamig 1-197-060.comset.com
alexander.olm+ia isdn59.rz.tu-ilmena
amythist abel-146.abel.co.uk
arcor dialin-kln42-4.arcor-ip.de
as4272 d40.spb.sitek.net
bayi0023 195.175.110.204
bbvrebel@bbvnet 206057.rad.tsai.es
be033660 pool04-194-7-45-122.uunet.b
bfas GO-A01-pool-244.tmns.net.au
bhcm00050 svr2-oxf.cableinet.net
bookaze meaux7-130.club-internet.fr
bs178109 dialup12.nivelles.skynet.be
bvallis ms01-378.vcr.istar.ca
ccc16234 msx-arh-17-10.ppp.cybercit
clickvd ti26a03-0045.dialup.online
clubint/cipm perpignan3-19.club-inte
clubint/erlik bourg-en-bresse2-23.cl
clubint/gcyril chartr1-96.abo.wanado
clubint/gib_step besancon8-115.club-
clubint/lebanni poitiers6-110.club-i
clubint/nono6 la-roche-sur-yon2-36.c
clubint/rbellec quimper2-119.club-in
clubint/rousself rouen3-196.club-int
cnicol pppath114.compulink.gr
d.lawrence2 tnt-1-54.easynet.co.uk
dagfolse ti32a02-0019.dialup.online.
davefld 207-172-81-111.s48.as2.ptr.e
demo ppp120.ath-users.acropolis.gr
dhuart ppp19.83.208.212.in-addr.arpa
dpadula d-ma-superpop-2-136.ici.net
drstrange 208-237-196-200.irv.jps.net
dtibinac ac12-p13-zg.tel.hr
dubergey bordeaux1-21.hol.fr
emlang m33-38.fh-niederrhein.de
eoghann dip-195-74-66-69.thenet.co.
EP157$IK compy-net.com
fabimigl a-pd10-47.tin.it
fdelacroix gate4-231.nordnet.fr
felfort rduesmd5p91.impsat.net.ar
fherfurt ppp-45.arco.de
fickv a-cr6-2.tin.it
fn025437 ip179.pool-07.flashnet.it
franzwla dialin12.bnet.at
FREE811383 ppp-353.telinco.net
froab082 dyn-25.dij.oleane.com
froag036 dyn-25.dij.oleane.com
fti/3XrQ3td tntaub1-155.abo.wanadoo.
fti/fqdWq2C bourge1-228.abo.wanadoo.
fti/jd100k0 poi9-103.abo.wanadoo.fr
fti/Toto_The_Great_One marse1-13
fti/upPackb tnttls17-22.abo.wanadoo.
fti/vETuPbz mans7-206.abo.wanadoo.fr
fti/VvU7pqh ang1-152.abo.wanadoo.fr
f_click ppp31.online.kharkov.com
gg48 ppp-105-159.villette.club-inter
ghizzu 195.130.232.123
gimalate a-rt2-58.tin.it
giovrosa ts1103.gpnet.it
gopery 194.226.123.151
Gsilverleaf dial-2-036-edm.worldga
guglielmo.ferri se-11.galactica.it
guru70 b2-76.b.vossnet.de
haase 141.45.187.5
hallima1 1.2.3.5
ho2274 port17.hof.baynet
i33124 129.142.210.3
iltsa saccess-01-008.magna.com.au
internet.deinet.alco011 das-1-56.sit
internet.hkinet.ipser9 slip139-92-34
internet.hkinet.sprite0 slip139-92-3
jccrough gdialup128.phnx.uswest.net
jonasth pm1-10.bahnhof.se
jrmp aV340110.asu.pla.net.py
jw1983 trzy.byd.top.pl
korzeniewski line7.hamm.netsurf.de
kuai0461 pm2-186.wineasy.se
kwdjc mw-pm2-14.wf.net
leni d4-eger.elender.hu
lexisralf 194.95.206.39
log10372 lyon199.dtr.fr
lu100854 193.193.150.38
mabaker utc-1-10.interlinx.qc.ca
magma r-2511-1.grifonline.it
mangra ppp-10.docnet.it
marmotte kip-7.hol.fr
maslanza a-mi44-21.tin.it
matteo www.centroin.it
mncar a-tv5.interbusiness.it
morris node139.net2.fundy.net
myk...@pratique.fr cyber43.toulouse.im
neil dip-195-74-66-228.thenet.co.uk
Nfrhelak modem0.greifswald.netsurf.d
niska MDCCCLXIV.dyn.saunalahti.fi
nk000057 neukunde004.subnetz.nordkom
pa2589 ip033.pool-310.flashnet.it
pasil CCXXI.rdyn.saunalahti.fi
pauxue engine24p12.maltanet.net
Pburstel isdn17.boerde.de
Pgoltz n242-121.berlin.snafu.de
ping4481 dialup139.charleroi.eunet.b
pleplae t00-55.antw.online.be
Ppic dialup37.wonder.ca
pppmmd ppp.kharkov.net
pppsurf board-07.darmstadt.netsurf.de
Pprimel ppp1-149.brb.snafu.de
ppwestra 8-153.dialup.surnet.ru
Pramboy n241-78.berlin.snafu.de
ptt8ct 195.66.162.147
pwba00576 usr159-bas.cableinet.co.uk
qwcer a-mt3-40.tin.it
rdruguet ras.ge04.cortex.ch
rmaeckle TCNS1-048.ras.uni-hohenheim
rstotzer portge11.worldcom.ch
s-141886 msx-08-1-11.1033.cybercity.
s-147297 p417-090.ppp.get2net.dk
s-181957 p136-05.ppp.get2net.dk
s-245097 dialup146-3-19.swipnet.se
s-617041 dialup239-7-14.swipnet.se
s-73282 dialup122-3-25.swipnet.se
s-818748 p141-59.ppp.get2net.dk
s.masey lon4-1.ukonline.co.uk
s1442727 ws39.public.fh-hamburg.de
sahlenaa du92-27.ppp.algonet.se
scalp01 ppp-101-58.villette.club-int
schwarts dynip43.informatik.uni-stut
shireman ppp05-ang2.mozcom.com
simareng 212.216.42.45
skamen ppp26.internaute.fr
skull 195.134.208.120
sof4uk 158.152.176.244
suc...@okay.net ip125.duisburg.ok
superbat bordeaux1-35.hol.fr
THeSMiTH tun-ad13.tver.fact400.ru
thomas ras189.avades.nl
thunderchild line45.kdt.de
Timm.Mueller board-57.darmsta
toenges DialIn41.Fact.Rhein-Ruhr.De
trash ppp-cst47.warszawa.tpnet.pl
ua01872 ip001.pool-07.flashnet.it
uc18 nz20.rz.uni-karlsruhe.de
uk,ppp,benn dialup-00-48.netcomuk.c
usep2316 v-mi1-028.Punto.IT
vague dyn208-6-76-221.lon.mnsi.net
voxel ppp2.nat.fr
vpqar a-rm29-45.tin.it
Vrmllion reggae-05-73.nv.iinet.net.
wgh du11.foehr.net
zversec al3-p118-zg.tel.hr


Keith Blakemore-Noble

unread,
Dec 4, 1998, 3:00:00 AM12/4/98
to
"DG" == "David Gerber" writes:

> Miami has a backdoor and seems to have it for a long time. Some
> people

Bullsh!t.

> actually managed to find how it works and started to steal passwords
> from people. It's very important to check if your login is on this
> list. I intentionally removed the passwords from it to avoid security
> problems.

One tiny little point you shoudl consider before making such unfounded
accusations agains Miami...

The list was created by DC, who have often spoken out against Holger
and Miami ever since Miami started detecting cracked keys.

Just answer me this very simple question, David...

IF, as you try to claim, it is Miami logging this info, then HOW THE
FSCK WOULD DC BE ABLE TO GET THE INFO, HMMM??

Asnwer - they wouldn't.

You still going to tell us publically that Miami is the source of the
problem? Woudl you be prepared to testify to that under oath in a court
of law, perhaps? Hmmmm?


To everyone else - it is, of course, good general advise to change your
password regularly anyway...

joe

unread,
Dec 4, 1998, 3:00:00 AM12/4/98
to
** To reply in e-mail, remove "jucfej." from address **

On 04 Dec 98 00:06:27 +0100, "David Gerber" wrote about Miami backdoor, warning!:


> Miami has a backdoor and seems to have it for a long time. Some people
> actually managed to find how it works and started to steal passwords from
> people. It's very important to check if your login is on this list. I
> intentionally removed the passwords from it to avoid security problems.

OK, but without some very very basic info about the password, this is
just info that any spammer has trolled from the ngs.

> If you are on the list, change your password as quickly as possible, and do
> not use Miami anymore.

<snips>

> USERNAME IP/ISP
>
> 00503201 ip405.nordwest.net
> 0600e142 194.243.31.199
> 0avolta Pescara4-3.tin.it
> 100111,463 md19-090.mun.compuse

<snips>

If you had given at least a minimal description of the password then this
would be plausible. For example, one or two characters and total number
of alphanumeric characters. But this list is just email passwords and
their domain names. Hell, any bulk email outfit already has this junk
no matter how much anti-spam we use. If you're going to make such
accusations against one of the most popular Amiga developers and the
premier Amiga TCP stack, you need to do much better than this.....joe

Troels Walsted Hansen

unread,
Dec 4, 1998, 3:00:00 AM12/4/98
to
In article <747ap4$shk$1...@news1.epix.net>, e...@jucfej.epix.net (joe) wrote:

>If you had given at least a minimal description of the password then this
>would be plausible. For example, one or two characters and total number
>of alphanumeric characters. But this list is just email passwords and
>their domain names. Hell, any bulk email outfit already has this junk
>no matter how much anti-spam we use. If you're going to make such
>accusations against one of the most popular Amiga developers and the
>premier Amiga TCP stack, you need to do much better than this.....joe

The list is real. But there is no concrete proof of a backdoor in Miami.

T r o e l s W a l s t e d H a n s e n
tro...@stud.cs.uit.no - http://www.cs.uit.no/~troels


Trevor Daley

unread,
Dec 4, 1998, 3:00:00 AM12/4/98
to
On 04-Dec-98 08:06:27 *David Gerber* wrote about Miami backdoor, warning!, so I
though I would say...

Hi All,

>Miami has a backdoor and seems to have it for a long time. Some people
>actually managed to find how it works and started to steal passwords from
>people. It's very important to check if your login is on this list. I
>intentionally removed the passwords from it to avoid security problems.

>If you are on the list, change your password as quickly as possible, and do
>not use Miami anymore.

The above statement is a total lie.

I am on that list and the entry dates back 6 months, also the entry is wrong.
I was using AmiTCP at the time and the only other program that had those details
is DCtelnet... I believe that the is the problem program.

I suggest that you be careful what you say as the bove is leaning towards
slander.

Ciao, Trev Daley.

<sb>A1200T 060/50 * 2meg Chip / 64meg EDO Fast Ram * CV64/3D P96
Trevor Daley E-Mail:- tld...@newave.net.au
South Australia ICQ: #12990261
Message written using *Thor* Version 2.5a on 4-Dec-98 11:08:06.
<sb>Live long and prosper


Neil Bothwick

unread,
Dec 4, 1998, 3:00:00 AM12/4/98
to
joe said,

> If you had given at least a minimal description of the password then this
> would be plausible. For example, one or two characters and total number
> of alphanumeric characters. But this list is just email passwords and
> their domain names.

I've seen the full list and it includes login details, all someone
needs to log into your account, send spam from your mail server etc.

However, that doesn't mean the details have come from Miami.

It does demonstrate that there is something insecure floating around,
and you should never trust any password long term. Change it at least
once a month or you will get hacked, sooner or later.


Neil
--
Neil Bothwick - http://www.wirenet.co.uk icq://16361788
Connected via Wirenet,The UK's first Amiga-only internet access provider
--
Beware of the dragon: Trespassers will be flame-grilled


Jonathan Gapen

unread,
Dec 4, 1998, 3:00:00 AM12/4/98
to
David Gerber wrote:
>Miami has a backdoor and seems to have it for a long time. Some people

If this is anything more than more lame slander by a bunch of creeps
who got their egos bruised, I'd like to see a post to BUGTRAQ detailing
the exploit. It's the professional thing to do.

--
Jonathan Gapen - sysadmin - biker - caver - collecter of old computers
I think you know exactly what I mean when I say it's a shpadoinkle day.

Milt

unread,
Dec 4, 1998, 3:00:00 AM12/4/98
to
Nice try.... its not a "backdoor" in Miami. People I have been speaking
too have suspicious its something in pirated copies of internet
software...or keymaker programs and such... but Miami is not the
problem. At least not legally registered copies of Miami since I have
seen the list and many people i know that use Miami are NOT in that
list. But people I know that regularly pirate software are on that list.


Alan L.M. Buxey

unread,
Dec 4, 1998, 3:00:00 AM12/4/98
to
On 04 Dec 98 00:06:27 +0100 ,David Gerber posted the following:
: Miami has a backdoor and seems to have it for a long time. Some people

: actually managed to find how it works and started to steal passwords from
: people. It's very important to check if your login is on this list. I
: intentionally removed the passwords from it to avoid security problems.

the backdoor is not in Miami. the "backdoor" is actually in a couple of
released DC clients - eg DCTelnet.

alan

kr...@nordicglobal.com

unread,
Dec 4, 1998, 3:00:00 AM12/4/98
to
In article <54741.642T...@deckpoint.ch>,

"David Gerber" <za...@deckpoint.ch> wrote:
> Miami has a backdoor and seems to have it for a long time.

No, it does not, and it never has. That password list was compiled
by different means, that are not related to Miami. For more
information please see "http://www.nordicglobal.com/pwlistinfo.txt"

> Some people
> actually managed to find how it works and started to steal passwords from
> people.

Nonsense. No such mechanism in Miami exists.

> It's very important to check if your login is on this list.

No, that is immaterial. What IS important is to change your password,
IMMEDIATELY, regardless of whether you are on the list or not.
Chances are the backdoor that cracker planted is still active, and
that he is still getting new passwords from unsuspecting users every
day. Just because you are not on the list does not mean you are safe.

> If you are on the list, change your password as quickly as possible, and do
> not use Miami anymore.

Miami has nothing to do with this. Whatever backdoor the cracker
planted on your system, it is independent of Miami and will continue
to operate and to export your password even if you change protocol
stacks.

--
Holger Kruse
kr...@nordicglobal.com

-----------== Posted via Deja News, The Discussion Network ==----------
http://www.dejanews.com/ Search, Read, Discuss, or Start Your Own

Matt Sealey

unread,
Dec 4, 1998, 3:00:00 AM12/4/98
to
David Gerber <za...@deckpoint.ch> wrote in message
news:54741.642T...@deckpoint.ch...

>Miami has a backdoor and seems to have it for a long time.
Absolute bollocks. Miami doesn`t have a backdoor - for a program to have a
backdoor, the programmer has to PUT it there, either as a result of a bug or
on purpose. Holger Kruse wouldn`t put a bakdoor in Miami, an d I very much
doubt it has bugs that are THAT serious!

>Some people
>actually managed to find how it works and started to steal passwords from
>people.

As people have said in this thread, Digital Corruption are the culprits,
using wierd (and wired) clients for Telnet and the like to steal passwords.

> It's very important to check if your login is on this list. I
>intentionally removed the passwords from it to avoid security problems.

Bullshit.

>If you are on the list, change your password as quickly as possible, and do
>not use Miami anymore.

I`m not ditching Miami because you say so. The sad thing is that this looks
so much
like a hoax or a trick - if it was real, people would be REALLY panicing..

>@BEGIN_FILE_ID.DIZ********************************************
>
> PASSWORDS FROM AMIGA USERS WORLDWIDE
> SCORED BY USING HOLGER KRUSES OWN
> KNOWN AND WELL TALKED ABOUT BACKDOOR
> IN MIAMI TCP STACK...

Hackers and Hoaxers tend to write in capitals to get peoples attention.

> CAN HE STILL DENY
> IT AFTER THIS??? FUCK YOU HOLGER KRUSE!

Looks like they`re trying to get Holger off their back by quitting the
development of Miami. Got something to hide? Like craked keyfiles perhaps?


>SOME FUCKING LOGS AND PASSWORDS MIGHT BE INVALID BECAUSE THIS LIST HAS

^^^^^^^^^^ Gratuitous swearing is a lamer attribute, especially when it is
grammatically incorrect.

>HOLGWHORE KRUDE - REMEMBER THE NAME BECAUSE I HAVE JUST STARTED ON MY
>REIGN OF H/P/A/V ON THE MIGHTY AMIGA!

What a dickhead.

>
> YET !MORE! PASSWORDS FROM AMIGA USERS
> SCORED BY USING HOLGER KRUSES MIAMI
> BACKDOOR. I WONT STOP UNTIL HOLGER
> ADMITS WHAT EVERYONE KNOWS, THAT HIS
> TCP STACK HAS HOLES LIKE THE GRAND
> CANYON! ...CAN HE !STILL! DENY IT AFTER
> THIS??? (PROBABLY) FUCK YOU HOLGER KRUSE!

Again..!

>OK OK SO PEOPLE ARE TELLING ME AND TALKING AND SAYING THAT THE
>BASTARD IS STILL IN PUBLIC DENIAL! WELL MR.FUCKING KRUSE LETS

More gratuitous swearing. I bet they live in council accomodation. Sorry if
I offended well-meaning council accomodation people!

>JUST KEEP THEM ROLLING OUT UNTIL YOU FINALLY CRACK UNDER THE
>USERS PRESSURE AND TELL ALL WHAT THE FUCK YOU HAVE BEEN CODING
>INTO MIAMI!

And more.

It`s all crap. Don`t anyone worry.
--
Matt Sealey, mw...@le.ac.uk
Distributed Systems Support,
University of Leicester
--

Neil Bothwick

unread,
Dec 4, 1998, 3:00:00 AM12/4/98
to
Matt Sealey said,

>> It's very important to check if your login is on this list. I
>>intentionally removed the passwords from it to avoid security problems.

> Bullshit.

>>If you are on the list, change your password as quickly as possible, and do
>>not use Miami anymore.

> I`m not ditching Miami because you say so. The sad thing is that this looks
> so much
> like a hoax or a trick - if it was real, people would be REALLY panicing..

It may be a trick, it's not a hoax. The data on the original list is
real, even if the claims about the source are not.

> It`s all crap. Don`t anyone worry.

Unfortunately it's not all crap, and you should worry. I would
recommend that anyone changes their password regularly.

I suspect that the information on this list has been culled from a
number of sources, especially as it contains information on account
that are only used via PCs!


Neil
--
Neil Bothwick - http://www.wirenet.co.uk icq://16361788
Connected via Wirenet,The UK's first Amiga-only internet access provider
--

"Criminal Lawyer" is a redundancy.


Johan Ronnblom

unread,
Dec 4, 1998, 3:00:00 AM12/4/98
to
Neil Bothwick wrote:
> Matt Sealey said,

> Unfortunately it's not all crap, and you should worry. I would
> recommend that anyone changes their password regularly.
>
> I suspect that the information on this list has been culled from a
> number of sources, especially as it contains information on account
> that are only used via PCs!

Yes. I wrote to warn a friend who is on the list, and he said he had
been contacted by his ISP a few months ago since the passwords had
somehow gotten out. It was not a Miami-related or even Amiga-related
problem.
The people who claim there are backdoors in Miami should shut up unless
they can tell exactly where (at which bytes!) in Miami the 'backdoor'
exists, so that it can be checked. I'm using Miami every day, and I feel
completely safe.

/Johan Rönnblom, Team Amiga

Alan L.M. Buxey

unread,
Dec 4, 1998, 3:00:00 AM12/4/98
to
On Fri, 04 Dec 1998 13:42:34 GMT ,kr...@nordicglobal.com posted the following:

: Nonsense. No such mechanism in Miami exists.

holger, is it possible to have Miami open up some sort of "log window"
that shows all connections and protocols that are currently active/used?

similar to "netstat" but a bit mroe friendly?

Then when people run clients or hosts they can see if an SMTP xfer has
just occurred etc

alan

Holger Kruse

unread,
Dec 4, 1998, 3:00:00 AM12/4/98
to
In comp.sys.amiga.datacomm Alan L.M. Buxey <kc...@central.susx.ac.uk> wrote:
> holger, is it possible to have Miami open up some sort of "log window"
> that shows all connections and protocols that are currently active/used?
> similar to "netstat" but a bit mroe friendly?

Miami does not have any such feature built-in, but there may be
an ARexx or Shell script for that on Aminet, based on netstat.

--
Holger Kruse kr...@nordicglobal.com
http://www.nordicglobal.com
NO COMMERCIAL SOLICITATION !


amig...@my-dejanews.com

unread,
Dec 4, 1998, 3:00:00 AM12/4/98
to
In article <7491nr$14f$1...@news.iag.net>,
>--

How in the dickens am I supposed to register Miami 3.0 when I'm not on the Web
with my Amiga? The program has an online registration wizard.
--
vr,[joe]
2-A1000; 1-A1200/68030/50; 1-A2000; 1-B2000 1-A3000

Fredrik Zetterlund

unread,
Dec 4, 1998, 3:00:00 AM12/4/98
to
On 04-Dec-98 15:42:47 did Johan Ronnblom write something about Re: Miami
backdoor, warning!:

I can only confirm (Big thanks anyway, Johan!). It was NOT related
to Miami as I don't use it... (Go figure!).
It was some 'sniffer' who traced all manual logins to the Unixshell account.


--
Mailto:fra...@canit.se http://www.canit.se/~frallan
ICQ:15114175 http://www.canit.se/~frallan/suab


Kirk Strauser

unread,
Dec 4, 1998, 3:00:00 AM12/4/98
to
amig...@my-dejanews.com wrote:

>How in the dickens am I supposed to register Miami 3.0 when I'm not
>on the Web with my Amiga? The program has an online registration wizard.

The idea is that you can get online using the unregistered version. Then
you can use that online session to register. See, there's no
contradiction. :)

Keith Blakemore-Noble

unread,
Dec 4, 1998, 3:00:00 AM12/4/98
to
"amiga" == "amig...@my-dejanews.com" writes:

> How in the dickens am I supposed to register Miami 3.0 when I'm not
> on the Web with my Amiga? The program has an online registration
> wizard.

Erm, use the Online Registration Wizard, of course!!

Seriously, it will connect and register you (by using the Miami eval
version which it comes with). It's vey painless, extremely easy and
VERY quick.

HTH,
Keith
--
http://www.BuiltWithAmiga.org Member of Team *AMIGA* and ICOA


Gary Peake

unread,
Dec 5, 1998, 3:00:00 AM12/5/98
to
kr...@iag.net scribed to us about Re: Miami backdoor, warning! in
comp.sys.amiga.misc

>In comp.sys.amiga.datacomm Alan L.M. Buxey <kc...@central.susx.ac.uk> wrote:
>> holger, is it possible to have Miami open up some sort of "log window"
>> that shows all connections and protocols that are currently active/used?
>> similar to "netstat" but a bit mroe friendly?

>Miami does not have any such feature built-in, but there may be
>an ARexx or Shell script for that on Aminet, based on netstat.

We would appreciate your advice or recommendation. Most of us would rather know
you looked at it and feel it is safe than to just go out blind and put something
on our systems that DOES open up a hole?

Any personal recommendations or would you consider adding something like that
for a small donation to the cause? :)

Gary Peake

unread,
Dec 5, 1998, 3:00:00 AM12/5/98
to
kr...@nordicglobal.com scribed to us about Re: Miami backdoor, warning! in
comp.sys.amiga.misc

>In article <54741.642T...@deckpoint.ch>,


> "David Gerber" <za...@deckpoint.ch> wrote:
>> Miami has a backdoor and seems to have it for a long time.

>No, it does not, and it never has. That password list was compiled


>by different means, that are not related to Miami. For more
>information please see "http://www.nordicglobal.com/pwlistinfo.txt"

Good show Holger!!!

>> Some people
>> actually managed to find how it works and started to steal passwords from
>> people.

>Nonsense. No such mechanism in Miami exists.

Please don't feel like you even need to defend yourself. We all know where the
problems are and who the problems are. And to use a little English slang "it
ain't you!".

>> It's very important to check if your login is on this list.

>No, that is immaterial. What IS important is to change your password,


>IMMEDIATELY, regardless of whether you are on the list or not.
>Chances are the backdoor that cracker planted is still active, and
>that he is still getting new passwords from unsuspecting users every
>day. Just because you are not on the list does not mean you are safe.

Unless you use Miami and REGISTERED "LEGITIMATE" shareware or comercial apps.

>> If you are on the list, change your password as quickly as possible, and do
>> not use Miami anymore.

>Miami has nothing to do with this. Whatever backdoor the cracker


>planted on your system, it is independent of Miami and will continue
>to operate and to export your password even if you change protocol
>stacks.

Well, they have "tried" to get into mine and haven't succeeded yet. But I have
no DC apps at all here and what apps I do run are legitimate and legally
registered. Miami does a good job of alerting to any outside "interference" as
such and also a good job of keeping people out who shouldn't be in.

Holger Kruse

unread,
Dec 5, 1998, 3:00:00 AM12/5/98
to
In comp.sys.amiga.datacomm Gary Peake <gpe...@wt.net> wrote:
> Any personal recommendations or would you consider adding something like that
> for a small donation to the cause? :)

It's on my list, but currently not with a high priority. I have
been fairly swamped with work recently :)

Thomas Tavoly

unread,
Dec 5, 1998, 3:00:00 AM12/5/98
to

In article <54741.642T...@deckpoint.ch> "David Gerber" <za...@deckpoint.ch> writes:
> Miami has a backdoor and seems to have it for a long time.

FUD at work (Fear, Uncertainty, Doubt). And apparently some measure of
boredom and hate.

Surprise surprise, no proof of where this backdoor should be. If they
could actually prove it, a newsgroup posting or some trusted third
party confirmation would have surfaced ages ago.

BTW, I only used Miami a couple of times for testing purposes and the
login/host listed didn't match either (nor does it match for most of the
people on the list, as it's clearly consisting of dynamic dialin
hostnames). My account was hacked during the summer and this came up on IRC
in October and shortly after the list surfaced. From that discussion I
would surmise we have something like a passive trojan (i.e. not a backdoor,
and definitely not Miami, even though it may have trawled info from Miami
settings files) which sends info by SMTP or some other means. This could be
literally anything, a trojan hidden in a game like Quake, some other TCP
app/game/util, cracked software, or something completely unrelated like any
library or non network related utility. I doubt every piece of software on
Aminet could ever be checked for such a thing either.

For those on the list who don't even use an Amiga it's not even any of the
above, just some ISP or Windows/whatever security issue, back orifice,
netbus, browser, javascript, activex, mail overflow etc. etc. etc. issue,
some kind of network snooping/spoofing, a brute force attack, etc. etc. The
possibilities are limitless.

> Some people
> actually managed to find how it works and started to steal passwords from
> people. It's very important to check if your login is on this list. I
> intentionally removed the passwords from it to avoid security problems.

If you have some undetected trojan on your system this makes precious
little difference, it could reactivate any time and your new password goes
out again.

> If you are on the list, change your password as quickly as possible, and do
> not use Miami anymore.

I doubt it has anything to do with Miami, except maybe specific targeting
of Miami users by whatever does this (or rather whoever).

Since you can't run SnoopDos all the time, let alone detect suspicious
things with it amongst the huge flow of data (and there are various ways
around SnoopDos too), a utility monitoring outgoing traffic would be much
better (or a firewall..). Unfortunately AmiTCP does not show outgoing
connections through netstat, it doesn't show udp ports at all, you can't
close outgoing ports like you can with incoming ones, so Miami users are
actually safer.

...
_ . Thomas Tavoly
. _ // . aTm...@amiga.cistron.nl
. \X/ http://www.cistron.nl/~ttavoly
... 5.1


Holger Kruse

unread,
Dec 5, 1998, 3:00:00 AM12/5/98
to
In comp.sys.amiga.datacomm Thomas Tavoly <aTm...@amiga.cistron.nl> wrote:

> In article <54741.642T...@deckpoint.ch> "David Gerber" <za...@deckpoint.ch> writes:

> > Miami has a backdoor and seems to have it for a long time.

> FUD at work (Fear, Uncertainty, Doubt). And apparently some measure of
> boredom and hate.

The precise details how the list was compiled are known now,
and Miami was NOT involved. Please read my separate announcement
"Security Advisory for Amiga Intenet users", on Usenet or on
my web site.

Timothy Rue

unread,
Dec 5, 1998, 3:00:00 AM12/5/98
to
On 05-Dec-98 11:15:57 Holger Kruse <kr...@iag.net> wrote:
>In comp.sys.amiga.datacomm Thomas Tavoly <aTm...@amiga.cistron.nl> wrote:

>> In article <54741.642T...@deckpoint.ch> "David Gerber"
>> <za...@deckpoint.ch> writes:

>> > Miami has a backdoor and seems to have it for a long time.

>> FUD at work (Fear, Uncertainty, Doubt). And apparently some measure of
>> boredom and hate.

>The precise details how the list was compiled are known now,
>and Miami was NOT involved. Please read my separate announcement
>"Security Advisory for Amiga Intenet users", on Usenet or on
>my web site.

>--
>Holger Kruse kr...@nordicglobal.com
> http://www.nordicglobal.com
> NO COMMERCIAL SOLICITATION !


Holger, if it is at all possible, I'd like to see a list of known members
of the pirate group mentioned as well as any information verifying their
connection to this act (preferably that of after the fact legal
prosecution documentation).

In other words, I'd like to know who of these people have been giving me a
hard time thru such acts against me. As I have received acts that are
legally pursuable, and perhaps supportive in action against such people.

Thanks.

I the lighter side, given the info you have supplied with the additional
post, it verifies why I'm not on the list they posted. Thanks!

---
*3 S.E.A.S - Virtual Interaction Configuration (VIC) - VISION OF VISIONS!*
*~ ~ ~ Advancing How we Perceive and Use the Tool of Computers!*
Timothy Rue What's *DONE* in all we do? *AI PK OI IP OP SF IQ ID KE*
Email @ mailto:tim...@mindspring.com >INPUT->(Processing)->OUTPUT>v
Web @ http://www.mindspring.com/~timrue/ ^<--------<----9----<--------<
Search email/name @ http://www.dejanews.com for other puzzle parts/posts.


Gary Peake

unread,
Dec 5, 1998, 3:00:00 AM12/5/98
to
kr...@iag.net scribed to us about Re: Miami backdoor, warning! in
comp.sys.amiga.misc

>In comp.sys.amiga.datacomm Gary Peake <gpe...@wt.net> wrote:


>> Any personal recommendations or would you consider adding something like
>> that for a small donation to the cause? :)

>It's on my list, but currently not with a high priority. I have
>been fairly swamped with work recently :)

Then I will wait for you or someone else I trust to give us one. The
datatypes.library thing should serve as a warning to everyone ... don't use
software from people you don't know and trust!

Georg Rottlaender

unread,
Dec 5, 1998, 3:00:00 AM12/5/98
to
Hello Gary Peake (gpe...@wt.net)!

On 05 Dec 98 16:12:18 -0600 you wrote:

> Then I will wait for you or someone else I trust to give us one. The
> datatypes.library thing should serve as a warning to everyone ... don't use
> software from people you don't know and trust!

Wasn't this fake released through Aminet some time ago and called back
by the original author of the datatypes.library??

Bye!

Georg

--
Georg Rottlaender - Friedrich-Ebert-Str. 4 - D-53721 Siegburg
Phone: +49-2241-590230 - E-Mail: Georg.Ro...@home.ivm.de
Homepage: http://home.ivm.de/~Georg.Rottlaender
---------------- A Legend Tears Itself To Pieces ----------------


Dave Bartz@RR

unread,
Dec 5, 1998, 3:00:00 AM12/5/98
to
Holger,
It has to really frustrating to have to deal with this type of crap when
you are the author of such great software as yours! I think the
community needs to take up a collection for your time spent fixing
someone else's problem. Got an address where I can send you a Christmas
card with a five dollar bill in it?
Dave Bartz
Proud Member of AMICON(http://www.amicon.org)

Thomas Tavoly

unread,
Dec 6, 1998, 3:00:00 AM12/6/98
to

In article <74bm7t$d9b$1...@news.iag.net> Holger Kruse <kr...@iag.net> writes:

> > FUD at work (Fear, Uncertainty, Doubt). And apparently some measure of
> > boredom and hate.
>
> The precise details how the list was compiled are known now,
> and Miami was NOT involved.

Yes, I made that point in my posting. The trouble is that such things can
happen again, and the people behind it will probably resort to some other
mechanism and carrier. It's even possible there is already some other
source (apart from usual ISP attacks and OS vulnerabilities), you can't be
certain the datatypes.library was the only one. I'm also wondering why the
recalling of the fake library was never publicized or investigated whether
the fake version did not contain something harmful.

Rene Laederach

unread,
Dec 6, 1998, 3:00:00 AM12/6/98
to
Hello Gary!

Gary Peake typed this on 05 Dec 98 16:12:18 -0600 about 'Re: Miami
backdoor, warning!':


GP> > It's on my list, but currently not with a high priority. I have been
GP> > fairly swamped with work recently :)
GP>
GP> Then I will wait for you or someone else I trust to give us one. The
GP> datatypes.library thing should serve as a warning to everyone ...
GP> don't use software from people you don't know and trust!

My upload virus checker caught a "Polish Power" virus lately, and this
archive went through Aminet.

What you download from my BBS (well known, for people still guessing the
IP number - it's 212.40.12.130), I can say with a good certainity that it does
not contain a known virus. What doesn't exclude unknown virii, of course. :(

--
FIDO: 2:301/133 & 135 | Member We're returning!
Internet mu...@snoop.alphanet.ch | Team AMIGA - the true avantgarde

Alan L.M. Buxey

unread,
Dec 8, 1998, 3:00:00 AM12/8/98
to
On 04 Dec 98 18:04:05 +0100 ,Gerard Cornu posted the following:

: Yes, and don't use your amiga anymore, because all those
: login/pass/hostnames were stolen from Amigas!!

rubbish! a large proportion are from people who've never even used an
Amiga!

alan

Alan L.M. Buxey

unread,
Dec 8, 1998, 3:00:00 AM12/8/98
to
On Fri, 04 Dec 1998 20:46:20 GMT ,amig...@my-dejanews.com posted the following:

: How in the dickens am I supposed to register Miami 3.0 when I'm not on the Web


: with my Amiga? The program has an online registration wizard.

ummmm....you're using Miami, right? If so, then you're going to be
online, right? (if not, then WHY are you using it? 8-) )

alan

Alan L.M. Buxey

unread,
Dec 8, 1998, 3:00:00 AM12/8/98
to
On Sat, 5 Dec 98 16:09:54 MET ,Thomas Tavoly posted the following:

: settings files) which sends info by SMTP or some other means. This could be


: literally anything, a trojan hidden in a game like Quake, some other TCP
: app/game/util, cracked software, or something completely unrelated like any
: library or non network related utility. I doubt every piece of software on
: Aminet could ever be checked for such a thing either.

this is very very scarey actually - and can happen at anytime. how are
you to know that buried inside ANY file is a trojan of this type?

this time around it was a library file - but next time what? A game, a
gfx viewer?

I dont want to run snoopdos 100% but i may well have to!

alan

Alan L.M. Buxey

unread,
Dec 8, 1998, 3:00:00 AM12/8/98
to
On 05 Dec 98 16:12:18 -0600 ,Gary Peake posted the following:

: Then I will wait for you or someone else I trust to give us one. The
: datatypes.library thing should serve as a warning to everyone ... don't use


: software from people you don't know and trust!

well, we may as well format aminet and forget getting new software at
all! - come on, noone knew , lets say Holger as an example, until Miami
came to form. I dont know any developers ona personal level what do i
do?

I think we all have to look afetr each other here - when you d/l from
aminet, check the program. If everyone runs snoopdos a little more when
running new software we'll have it covered.

Legal action MUST be taken too
(Tim, maybe amiga.com can be contacted to help out?)

This sort of thing can also happen on PC's as well - dont know how
they'll defend themselves ;-)


I'm a "high risk" category user as I d/l more than 15Mb of aminet a week
and run it.

alan

Alan L.M. Buxey

unread,
Dec 8, 1998, 3:00:00 AM12/8/98
to
On Sun, 06 Dec 1998 23:40:10 +0100 ,Rene Laederach posted the following:

: What you download from my BBS (well known, for people still guessing the
: IP number - it's 212.40.12.130), I can say with a good certainity that it d=
: oes
: not contain a known virus. What doesn't exclude unknown virii, of course. :=
: (

when i ran my BBS I checked EVERY file for virii with all the latest
tools - each archive was checked by a script that used at least 4
checkers.

One day I'll get it back online (had to go offline as i moved and
couldnt be connected to the cable-phone at the newer place - i've moved
4 times since then (last year) so havent had the time

alan

Matt Sergeant

unread,
Dec 8, 1998, 3:00:00 AM12/8/98
to

Perhaps on a LAN.

--
<Matt email="ma...@teamamiga.org" />

| Fastnet Software Ltd | Perl in Active Server Pages |
| Perl Consultancy, Web Development | Database Design | XML |
| http://come.to/fastnet | Information Consolidation |

Matt Sergeant

unread,
Dec 8, 1998, 3:00:00 AM12/8/98
to
"Alan L.M. Buxey" wrote:
>
> I'm a "high risk" category user as I d/l more than 15Mb of aminet a week
> and run it.

Watch out for that new DCTelnet then ;-)

Neil Bothwick

unread,
Dec 8, 1998, 3:00:00 AM12/8/98
to
Matt Sergeant said,

>> ummmm....you're using Miami, right? If so, then you're going to be
>> online, right? (if not, then WHY are you using it? 8-) )

> Perhaps on a LAN.

And what do the first two letters of MIAMI stand for?

:-)


Neil
--
Neil Bothwick - http://www.wirenet.co.uk icq://16361788
Connected via Wirenet,The UK's first Amiga-only internet access provider
--
UNIX is the OS of the future and always will be...


Holger Kruse

unread,
Dec 8, 1998, 3:00:00 AM12/8/98
to
In comp.sys.amiga.datacomm Alan L.M. Buxey <kc...@central.susx.ac.uk> wrote:
> I think we all have to look afetr each other here - when you d/l from
> aminet, check the program. If everyone runs snoopdos a little more when
> running new software we'll have it covered.

Usually I would agree, but in this particular case SnoopDos would
not have helped. That fake datatypes.library has code to ensure
that its activity is invisible to SnoopDos.

> Legal action MUST be taken too
> (Tim, maybe amiga.com can be contacted to help out?)

Amiga Inc. has already been contacted.

Matt Sergeant

unread,
Dec 8, 1998, 3:00:00 AM12/8/98
to
Neil Bothwick wrote:
>
> Matt Sergeant said,
>
> >> ummmm....you're using Miami, right? If so, then you're going to be
> >> online, right? (if not, then WHY are you using it? 8-) )
>
> > Perhaps on a LAN.
>
> And what do the first two letters of MIAMI stand for?

I haven't got a clue - I always just figured Holger was a "Vice" fan. :)

Neil Bothwick

unread,
Dec 8, 1998, 3:00:00 AM12/8/98
to
Matt Sergeant said,

> Neil Bothwick wrote:

>> > Perhaps on a LAN.

>> And what do the first two letters of MIAMI stand for?

> I haven't got a clue - I always just figured Holger was a "Vice" fan. :)

ISTR Miami stands for Modem Internet on AMIga.


Neil
--
Neil Bothwick - http://www.wirenet.co.uk icq://16361788
Connected via Wirenet,The UK's first Amiga-only internet access provider
--

My Go this amn keyboar oesn't have any 's.


Michael M. Rye

unread,
Dec 8, 1998, 3:00:00 AM12/8/98
to
On Tue, 08 Dec 1998 16:12:05 +0000 Matt Sergeant
<ma...@teamamiga.org_NOSPAM> wrote:
>Neil Bothwick wrote:

>> Matt Sergeant said,

>> >> ummmm....you're using Miami, right? If so, then you're going to be
>> >> online, right? (if not, then WHY are you using it? 8-) )

>> > Perhaps on a LAN.

>> And what do the first two letters of MIAMI stand for?

>I haven't got a clue - I always just figured Holger was a "Vice" fan. :)

Actually, on earlier versions of Miami (i.e. around v1.x) the title
bar of the main Miami window would say:

Modem-based Internet for the Amiga

There's your answer.
--
|=========================================================================|
| Michael Rye | Infinitiv A1200T 030/MMU/882 50 MHz 22 MB RAM |
| UNIX/C Admin/Design | 2.2 Gig HD Surf Squirrel SupraExpress 56e V.90 |
| Team AMIGA |___NEC 16X SCSI-II CD-ROM Seagate TapeStor 8000___|
| mry...@at.uhc.com | Amiga 500 AdRAM 540 - 1 Chip/2 Fast 2 floppies |
|=========================================================================|
| "The future is not what it used to be." - G'Kar, Babylon 5 |
|=========================================================================|
Email address spam-proofed: .at and at. invalid parts of email address

Michael M. Rye

unread,
Dec 8, 1998, 3:00:00 AM12/8/98
to
On 08 Dec 98 14:00:45 +0000 "Neil Bothwick" <ne...@wirenet.co.uk> wrote:
> And what do the first two letters of MIAMI stand for?

"Modem-based Internet". At least that's what they stood for when it
was still at version 1.x (oh so long ago :-) ).

Neil Bothwick

unread,
Dec 8, 1998, 3:00:00 AM12/8/98
to
Michael M. Rye said,

> On 08 Dec 98 14:00:45 +0000 "Neil Bothwick" <ne...@wirenet.co.uk> wrote:
>> And what do the first two letters of MIAMI stand for?

> "Modem-based Internet". At least that's what they stood for when it
> was still at version 1.x (oh so long ago :-) ).

My point exactly :)


Neil
--
Neil Bothwick - http://www.wirenet.co.uk icq://16361788
Connected via Wirenet,The UK's first Amiga-only internet access provider
--

WWW: World Wide Wait


Oliver Kastl

unread,
Dec 9, 1998, 3:00:00 AM12/9/98
to
Alan L.M. Buxey wrote in message <74j620$t9c$9...@infa.central.susx.ac.uk>...

>
>I think we all have to look afetr each other here - when you d/l from
>aminet, check the program. If everyone runs snoopdos a little more when
>running new software we'll have it covered.


A clever trojan/virus/whatever would use packet level I/O avoiding
dos.library calls.
This would be unvisible for SnoopDos.

Oliver


Ruediger Kuhlmann

unread,
Dec 9, 1998, 3:00:00 AM12/9/98
to
Hi!

> A clever trojan/virus/whatever would use packet level I/O avoiding
> dos.library calls.
> This would be unvisible for SnoopDos.

Packet level I/O is visable with snoopdos, but you have to tell it.
But it creates a lot of unnecessary lines in the output.
That's one thing I hate of ixemul... :(.

Yours, RĂ¼diger.


Alan L.M. Buxey

unread,
Dec 10, 1998, 3:00:00 AM12/10/98
to
On Tue, 08 Dec 1998 13:15:28 +0000 ,Matt Sergeant posted the following:

: Watch out for that new DCTelnet then ;-)

oh, that one's fine I've never known a program to be able to format my
error ridden sys: partition so quickly! So i just renamed it to
FastFormat and i'm quite happy now 8-)

alan

Alan L.M. Buxey

unread,
Dec 10, 1998, 3:00:00 AM12/10/98
to
On 8 Dec 1998 16:18:25 GMT ,Holger Kruse posted the following:

: Usually I would agree, but in this particular case SnoopDos would


: not have helped. That fake datatypes.library has code to ensure
: that its activity is invisible to SnoopDos.

then we need a new tool that can monitor file-accesses better

alan

Matt Sealey

unread,
Dec 10, 1998, 3:00:00 AM12/10/98
to
>> "Modem-based Internet". At least that's what they stood for when it
>> was still at version 1.x (oh so long ago :-) ).
>
>My point exactly :)
>
You can use Miami deluxe over a LAN. So there!

--
Matt Sealey, mw...@le.ac.uk
Distributed Systems Support,
University of Leicester
--


Neil Bothwick

unread,
Dec 10, 1998, 3:00:00 AM12/10/98
to
Matt Sealey said,

>>> "Modem-based Internet". At least that's what they stood for when it
>>> was still at version 1.x (oh so long ago :-) ).
>>
>>My point exactly :)
>>
> You can use Miami deluxe over a LAN. So there!

I know that, I do it every day, although the original question was
about Miami... and my reply to you had a smiley :)

Here's another in case you missed the first :)


Neil
--
Neil Bothwick - http://www.wirenet.co.uk icq://16361788
Connected via Wirenet,The UK's first Amiga-only internet access provider
--

Oxymoron: Reagan memoirs.


Rated RR.

unread,
Dec 10, 1998, 3:00:00 AM12/10/98
to
> Oliver Kastl thought deeply about Re: Miami backdoor, warning! and wrote then:

> Alan L.M. Buxey wrote in message <74j620$t9c$9...@infa.central.susx.ac.uk>...
> >
> >I think we all have to look afetr each other here - when you d/l from
> >aminet, check the program. If everyone runs snoopdos a little more when
> >running new software we'll have it covered.

> A clever trojan/virus/whatever would use packet level I/O avoiding
> dos.library calls.
> This would be unvisible for SnoopDos.
>

This is exactly what has happened, check Holger Kruse's:

http://www.nordicglobal.com/news.html

There it says all.


--
EM@: dpu...@zesoi.fer.hr, rat...@usa.net AKA: Dalibor Puljiz
URL: http://islands.zesoi.fer.hr/~dpuljiz ICQ: 2463483
ORG: *WARP - Croatian Amiga Magazine* CTY: Croatia, Europe

I asked Jesus, "How much do you love me?"...
"This much," He answered, then He stretched out his arms, and died.


Jeff Grimmett

unread,
Dec 10, 1998, 3:00:00 AM12/10/98
to
Quoting Kc...@central.susx.ac.uk (alan L.m.:

K> : not have helped. That fake datatypes.library has code to ensure
K> : that its activity is invisible to SnoopDos.

K> then we need a new tool that can monitor file-accesses better

The source code for SnoopDos is available, so if the author isn't
supporting it (I have no idea if he is or not), why not make what we have
more robust? Unfortunately, I wouldn't know where to begin on that score
:-(


... Sometimes I wonder why it took mom so long to snap.

-- Via DLG v1.26

// Jeff Grimmett . ICQ 17300370 . ( Grimm...@Earthling.Net )
// (http://www.ald.net/dlg) . The home of DLG Pro BBOS

Gerard Sweeney / Hackers Anonymous

unread,
Dec 11, 1998, 3:00:00 AM12/11/98
to
Alan L.M. Buxey said

>>That fake datatypes.library has code to ensure

>> : that its activity is invisible to SnoopDos.
>

> then we need a new tool that can monitor file-accesses better

When are you going to write it then Alan? :-)

Toodle-pip!
Gerard
--
Gerard Sweeney - Hackers Anonymous/Team Amiga
Visit The Hackers Anonymous Speccy Playground for Hack Attack 3
where you're always likely to get a good POKE (fnar!).
Or look for speccy games using the NVG catalogue. All at:
http://fly.to/ha3 , http://fly.to/nvgcat or
http://www.geocities.com/SiliconValley/Lakes/4871

Gary Peake

unread,
Dec 11, 1998, 3:00:00 AM12/11/98
to
kc...@central.susx.ac.uk scribed to us about Re: Miami backdoor, warning! in
comp.sys.amiga.misc

>On 05 Dec 98 16:12:18 -0600 ,Gary Peake posted the following:

>: Then I will wait for you or someone else I trust to give us one. The
>: datatypes.library thing should serve as a warning to everyone ... don't use
>: software from people you don't know and trust!

>well, we may as well format aminet and forget getting new software at
>all! - come on, noone knew , lets say Holger as an example, until Miami
>came to form. I dont know any developers ona personal level what do i
>do?

I do not know Holger on a personal level either. I know him on a professional
level. His name is ON his products, he supports his products, he has a proven
track record of integrity, there are few if any complaints about bugs or money
sent and no keyfiles recieved.

These are the things we should all watch for with software. DCTelnet just has a
scary ring to it for me ... :)

--
Gary Peake PLEASE NOTE NEW EMAIL ADDRESS!!

Team AMIGA
gpe...@owlnet.net
http://www.owlnet.net (coming soon)


Alan L.M. Buxey

unread,
Dec 15, 1998, 3:00:00 AM12/15/98
to
On 11 Dec 1998 12:29:35 GMT ,Gerard Sweeney / Hackers Anonymous posted the following:

: > then we need a new tool that can monitor file-accesses better

: When are you going to write it then Alan? :-)

I would if I could but I cant . I would say that I would be very happy
if someone were to give us a new system monitor that can do SnoopDOS and
more - happy enough to pay for such a tool (SnoopDOS has facilitated
the running of many programs on my Amiga)

alan

ch...@sympatico.ca

unread,
Dec 18, 1998, 3:00:00 AM12/18/98
to
If anyone knows how to get onto the Internet or WWW w/ an Amiga 1000,
PLEASE let me know.

Thanks!
ch...@sympatico.ca
mailto:ch...@sympatico.ca

Alan L.M. Buxey

unread,
Dec 18, 1998, 3:00:00 AM12/18/98
to
On Fri, 18 Dec 1998 05:38:31 GMT ,ch...@sympatico.ca posted the following:
: If anyone knows how to get onto the Internet or WWW w/ an Amiga 1000,
: PLEASE let me know.

more memory, upgrade OS to > 2.0 then use Miami

alan

Andrew

unread,
Dec 21, 1998, 3:00:00 AM12/21/98
to
On the 8 Dec 1998 12:28:48 GMT Alan L.M. Buxey wrote some drible and this what I think,

> This sort of thing can also happen on PC's as well - dont know how
> they'll defend themselves ;-)
The big problem wright now on PC side of things is *Back Orifice*
which gives full access to HD over the net when the PC user is
on-line. Total Read/Write access, so you could send then a Virus and
woun't know about it & could log on to there system and gain the
code's as in Miama backdoor problem. Or anything, as you can see this
makes the problem with Miami looks very tame compared to
this situation.

If you are really against this sort of thing or just want to be
the first to be in the know, then why not join *Amiga Security*
mailing list.

http://www.onelist.com/subscribe.cgi/amisecurity

Marion E. Wyatt

unread,
Dec 23, 1998, 3:00:00 AM12/23/98
to

Or OS3.1 even better.
--
AmiScorp ... Amiga3000 PPC

Andrew

unread,
Dec 25, 1998, 3:00:00 AM12/25/98
to
On the 10 Dec 1998 14:57:50 GMT Alan L.M. Buxey wrote some drible and this what I think,

> On 8 Dec 1998 16:18:25 GMT ,Holger Kruse posted the following:
>
> : Usually I would agree, but in this particular case SnoopDos would
> : not have helped. That fake datatypes.library has code to ensure

> : that its activity is invisible to SnoopDos.
>
> then we need a new tool that can monitor file-accesses better
>
Problem with that it is man made, so can be man broken :(

0 new messages