LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 01-19-2006, 12:58 PM   #1
alok.rhct
Member
 
Registered: Dec 2005
Posts: 75

Rep: Reputation: 16
help me


Let us assume you are managing a Linux server supporting an
Ecommerce website. Let us also assume that you have secured the server.
You removed telnet from all servers and installed the more secure ssh.
Let us say that the firewall configuration is as follows

conduit permit tcp host 192.168.5.10 eq 80 any
conduit permit tcp host 192.168.5.10 eq 443 any
conduit permit tcp host 192.168.5.10 eq 22 any

Suppose if a lower level tech calls you up at the middle of the night at
your home and says that he cannot ssh into one of the servers. Now you
try to log into the server from home using ssh, the first time you type
the passwd, it asks passwd again. You think you mistyped it and type
again. Now you are allowed into the server. What are the steps you will
take to make sure that the server is fine.

2)Suppose you figure out from the firewall logs that the webserver was
attacked from outside over port 22 and then used to connect an outside
server, what could be the most likely attack or vulnerability the
attacker used to compromise the webserver? What clues can you get from
your first attempts to log into the server using ssh? Where does this
clue point to? What will be your next course of action? What else you
could have done to prevent such an attack? Please answer all the
questions raised under this scenario.
 
Old 01-19-2006, 01:45 PM   #2
nilleso
Member
 
Registered: Nov 2004
Location: ON, CANADA
Distribution: ubuntu, RHAS, and other unmentionables
Posts: 372

Rep: Reputation: 31
copy'n'pastin your homework
 
Old 01-19-2006, 01:46 PM   #3
linmix
Senior Member
 
Registered: Jun 2004
Location: Spain
Distribution: FC5
Posts: 1,993
Blog Entries: 1

Rep: Reputation: 46
Which book were you supposed to read that has the answers. I'd like to have a look at it
 
Old 01-19-2006, 03:29 PM   #4
michaelk
Moderator
 
Registered: Aug 2002
Posts: 25,746

Rep: Reputation: 5925Reputation: 5925Reputation: 5925Reputation: 5925Reputation: 5925Reputation: 5925Reputation: 5925Reputation: 5925Reputation: 5925Reputation: 5925Reputation: 5925
Per the LQ Rules, Do not expect LQ members to do your homework - you will learn much more by doing it yourself.
http://www.linuxquestions.org/rules.php
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 05:15 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration