LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 07-15-2012, 11:24 AM   #1
segmentation_fault
Member
 
Registered: Sep 2008
Location: Ioannina, Greece
Distribution: Gentoo
Posts: 332

Rep: Reputation: 55
Threads about pc taken over


Is it just my idea, or it's a fact that threads about a pc been compromised are popping up quite frequently?

I am a linux user since 2006, I have internet connection since 2008. I have a dc server which runs 24/7 also connected to the internet. I have never used any special firewall or something; just "ALL: ALL" on hosts.deny and my trusted IPs on hosts.allow. I get about a dozen of shh attempts on each PC (sometimes I retaliate, too :P). In 4 years of internet experience, my systems have never been compromised in any way (of course I have disabled root ssh login and I use strong passwords). I don't remember reading a post about a system been taken over before here on LQ (citation needed )

So my question is, have the attacks been more frequent, indeed? Are these false alarms? Has the Linux been "more" targeted by crackers.
 
Old 07-15-2012, 01:02 PM   #2
fogpipe
Member
 
Registered: Mar 2011
Distribution: Slackware 64 -current,
Posts: 550

Rep: Reputation: 196Reputation: 196
I have been using linux since around 96 and i have seen some interesting things, compromised machines where system utilities like ps and netstat have been replaced with shell scripts that grep -v cracker processes for instance, but i have never seen anything like some of the stuff people have posted recently. OTOH im not totally discounting it, attackers have become more sophisticated no doubt, but i would have to actually see some of the stuff i have heard about recently to credit it.

One of the recent posts was about a machine (iirc) that had an infected mbr, where the virus or whatever, even survived re-install of a boot loader. I wouldnt have imagined that was possible.
 
Old 07-15-2012, 01:33 PM   #3
NyteOwl
Member
 
Registered: Aug 2008
Location: Nova Scotia, Canada
Distribution: Slackware, OpenBSD, others periodically
Posts: 512

Rep: Reputation: 139Reputation: 139
It never happens to you ... until it happens to you

I think it's like anything else in the emdia (traditional or otherwise) that while itm may be a bit more prevalent, you also hear more about it when it does occur.
 
Old 07-15-2012, 03:25 PM   #4
salasi
Senior Member
 
Registered: Jul 2007
Location: Directly above centre of the earth, UK
Distribution: SuSE, plus some hopping
Posts: 4,070

Rep: Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897
It is actually a bit difficult to tell, because a lot of the more dramatic threads should be filed under 'inexperienced and paranoid*' rather than real exploits, and quite a few are 'what should I do to prevent this particular issue..', neither of which should really be counted as actual exploits.

(* ...better than 'inexperienced and couldn't give a stuff )
 
Old 07-15-2012, 04:04 PM   #5
jefro
Moderator
 
Registered: Mar 2008
Posts: 21,976

Rep: Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623
There is an entire criminal world out there working day and night to steal. I'd guess they found that limiting their efforts to only Windows machine limited criminal profits. They decided to branch out.

I am not usually paranoid, I just don't trust anyone.

Last edited by jefro; 07-15-2012 at 04:05 PM.
 
Old 07-15-2012, 05:35 PM   #6
Terminal_Cowboy
Member
 
Registered: Jun 2012
Distribution: Gentoo (Host), Arch (Guest), FreeBSD9, Android 2.3.6
Posts: 32

Rep: Reputation: Disabled
I wonder if those who said their linux machine were compromised were doing everything as root. No matter the OS platform, one should never do everything as root/admin except for administrating purposes.

Last edited by Terminal_Cowboy; 07-15-2012 at 05:40 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
some threads are become unnoticed because of large number of continious threads deepak_cucek LQ Suggestions & Feedback 9 08-20-2009 11:21 PM
Execution threads vs normal threads jonty_11 Linux - General 2 03-26-2008 10:37 AM
"Find all threads started by user" not showing all threads Nylex LQ Suggestions & Feedback 3 12-28-2005 08:28 PM
Java threads listed using kill -3 does not contain all threads found using ps -auxww coneheed Programming 2 11-14-2005 08:57 AM
Java Threads vs Native Threads rjmendez Programming 0 08-16-2004 05:58 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 07:07 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration