| Notices |
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
Are you new to LinuxQuestions.org? Visit the following links:
Site Howto |
Site FAQ |
Sitemap |
Register Now
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
 |
GNU/Linux Basic Guide
This 255-page guide will provide you with the keys to understand the philosophy of free software, teach you how to use and handle it, and give you the tools required to move easily in the world of GNU/Linux. Many users and administrators will be taking their first steps with this GNU/Linux Basic guide and it will show you how to approach and solve the problems you encounter.
Click Here to receive this Complete Guide absolutely free. |
|
 |
Posted 10-03-2009 at 04:52 AM by unSpawn
Updated 04-01-2012 at 04:18 PM by unSpawn
(//Enhanced logwatch/scripts/services/http diff, added Snort ET SID 2010920 rule and fail2ban regex example, fixed commas (thanks leslie_jones).)
As I'm seeing more questions about (badly coded) web applications spawning rogue processes I wonder why people don't read their logs. Attacks require reconnaissance so keeping an eye on anything that looks like a prelude enables you to take measures. And please spend time updating when updates are released, installing apps properly (like not leaving the installation files around when docs remind you not to), hardening (any IDS, mod_security, Gotroot rulesets, mod_evasive or equivalent, PHPIDS, Suhosin,...
|
Moderator
|
|
Views 2905
Comments 0
|
 |
Posted 08-05-2009 at 09:47 AM by unSpawn
Updated 08-05-2009 at 09:49 AM by unSpawn
Take a peak at RKH's SF CVS stats and you will see that activity picked up again. Currently the RKH 1.3.5(-dev) Changelog (rev1.119) lists 16 bugfixes, 13 new items, 14 changes and counting.
It was a bit sad to notice some of the existing signatures were incomplete though. And while everyone knows breaches of security "the old school rootkit way" have dropped to nil, RKH aims to be complete. So I'll be replaying rootkit installs again and working on improving rootkit checks...
|
Moderator
|
|
Views 1363
Comments 0
|
 |
Posted 07-09-2009 at 06:46 AM by unSpawn
Eiciel allows you to visually edit file ACL entries. You can add and remove users and groups who will be granted permissions through the graphical interface. Eiciel can be used as stand-alone application and as Nautilus extension.
ACL: http://bestbits.at
Eiciel: http://rofi.roger-ferrer.org/eiciel/
Also-see: http://www.cs.bham.ac.uk/~nrs/jfacl/ (Java-based UI)
I didn't see no package but I know it is in Fedora-extras, I just didn't want to rebuild it....
|
Moderator
|
|
Views 1836
Comments 0
|
 |
Posted 07-03-2009 at 05:07 AM by unSpawn
Torsocks: http://code.google.com/p/torsocks/
Code:
# No debuginfo:
%define debug_packages %{nil}
%define debug_package %{nil}
#
%define name torsocks
%define ver 1.0
%define rel 1
%define buildver %{ver}-gamma
#
# Configuration switches for rebuilding (1=yes 0=no).
# Force dns lookups to use tcp? (config switch --enable-socksdns)
%define enablesocksdns 0
%{?build_enablesocksdns:%define enablesocksdns
...
|
Moderator
|
|
Views 1796
Comments 0
|
 |
Posted 07-01-2009 at 07:35 PM by unSpawn
Like before here's some results of running BitDefender, ClamAV and F-prot on over 11K of files containing Rootkits, LKM's and other goodies. Because of what I do most of the files are GNU/Linux related. (I run AV like a pentester would run metasploit against a networked entity.) I'm well aware of the AV-on-GNU/Linux-yes-or-no debate and this is not the place to go into that: search LQ or open up a thread if you need to discuss validity.
The commercial AV market is kind of an odd...
|
Moderator
|
|
Views 2188
Comments 0
|
All times are GMT -5. The time now is 01:01 AM.
|
|
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.
|
Latest Threads
LQ News
|
|