LinuxQuestions.org
LinuxAnswers - the LQ Linux tutorial section.
Go Back   LinuxQuestions.org > Blogs
User Name
Password

Notices

Old

Logwatch, webserver logs, PHP malarky

Posted 10-03-2009 at 05:52 AM by unSpawn
Tags logwatch, patch, php

As I'm seeing more questions about (badly coded) web applications spawning rogue processes I wonder why people don't read their logs. Attacks require reconnaissance so keeping an eye on anything that looks like a prelude enables you to take measures. And please spend time updating when updates are released, installing apps properly (like not leaving the installation files around when docs remind you not to), hardening (any IDS, mod_security, Gotroot rulesets, mod_evasive or equivalent, PHPIDS, Suhosin,...
Moderator
Posted in Uncategorized
Views 206 Comments 0 unSpawn is offline Edit Tags
Old

Rootkit Hunter 1.3.5-dev progress

Posted 08-05-2009 at 10:47 AM by unSpawn
Updated 08-05-2009 at 10:49 AM by unSpawn

Take a peak at RKH's SF CVS stats and you will see that activity picked up again. Currently the RKH 1.3.5(-dev) Changelog (rev1.119) lists 16 bugfixes, 13 new items, 14 changes and counting.

It was a bit sad to notice some of the existing signatures were incomplete though. And while everyone knows breaches of security "the old school rootkit way" have dropped to nil, RKH aims to be complete. So I'll be replaying rootkit installs again and working on improving rootkit checks...
Moderator
Posted in Uncategorized
Views 397 Comments 0 unSpawn is offline Edit Tags
Old

Eiciel .spec

Posted 07-09-2009 at 07:46 AM by unSpawn

Eiciel allows you to visually edit file ACL entries. You can add and remove users and groups who will be granted permissions through the graphical interface. Eiciel can be used as stand-alone application and as Nautilus extension.

ACL: http://bestbits.at
Eiciel: http://rofi.roger-ferrer.org/eiciel/
Also-see: http://www.cs.bham.ac.uk/~nrs/jfacl/ (Java-based UI)

I didn't see no package but I know it is in Fedora-extras, I just didn't want to rebuild it....
Moderator
Posted in Uncategorized
Views 466 Comments 0 unSpawn is offline Edit Tags
Old

Torsocks .spec

Posted 07-03-2009 at 06:07 AM by unSpawn

Torsocks: http://code.google.com/p/torsocks/

Code:
# No debuginfo:
%define debug_packages	%{nil}
%define debug_package %{nil}
#
%define name torsocks
%define ver 1.0
%define rel 1
%define buildver %{ver}-gamma
#
# Configuration switches for rebuilding (1=yes 0=no).
# Force dns lookups to use tcp? (config switch --enable-socksdns)
%define enablesocksdns 0
%{?build_enablesocksdns:%define enablesocksdns
...
Moderator
Posted in Uncategorized
Views 531 Comments 0 unSpawn is offline Edit Tags
Old

Non-authoritative scan results of BitDefender, ClamAV and F-prot

Posted 07-01-2009 at 08:35 PM by unSpawn
Tags antivirus

Like before here's some results of running BitDefender, ClamAV and F-prot on over 11K of files containing Rootkits, LKM's and other goodies. Because of what I do most of the files are GNU/Linux related. (I run AV like a pentester would run metasploit against a networked entity.) I'm well aware of the AV-on-GNU/Linux-yes-or-no debate and this is not the place to go into that: search LQ or open up a thread if you need to discuss validity.

The commercial AV market is kind of an odd...
Moderator
Posted in Uncategorized
Views 576 Comments 0 unSpawn is offline Edit Tags


All times are GMT -5. The time now is 08:13 PM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
RSS2  LQ Podcast
RSS2  LQ Radio
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration