LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 03-10-2003, 02:16 PM   #1
bankrupt
LQ Newbie
 
Registered: Jul 2001
Location: Arizona
Distribution: RH7.3 Kernal 2.4.2
Posts: 22

Rep: Reputation: 15
Searching out rough Linux Servers


I am trying to find a rough Linux server that I am told is on my network. Anyone have any idea how I can sniff it out? I have never attempted anything like this before and don't have the slightest idea how to do it or if it is even possible.

Thanks in advance!

 
Old 03-10-2003, 03:51 PM   #2
peter_robb
Senior Member
 
Registered: Feb 2002
Location: Szczecin, Poland
Distribution: Gentoo, Debian
Posts: 2,458

Rep: Reputation: 48
Errr, rough?

 
Old 03-11-2003, 08:12 AM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Guess he means he's gotta find some "rogue" server.

What approach you take depends IMHO on what "signs" you've gotten (you don't mention any details). For instance if you received a Black Ice or in other ways automated report, you should archive it carefully in /dev/null and put the sender in your killfilter, but if you've received a CERT, Dshield or other report from, say, someone's upstream ISP, they usually have included hints like ASCII tcpdumps or (IDS/firewall/sys) logs you should be able to work with.
The other dependancies before you work out what to do could include actually *knowing* what's on the LAN. If you don't maintain ingress/egress logs, and if you haven't got a clue about what's happening, and if there's no weird stuff in the DHCP logs, and if these boxen are for workers/drones/humans, you could log everything to/from the LAN (the ingress/egress logs), (and just mail a polite notification and) nmap the heck out of them for starters.
If OTOH you *know* some boxen are servers, and maybe have fragile stuff on 'em that a scan could break, single 'em out and comb 'em over with a slow nmap scan, follow up with a manual audit of the boxen's logs (remote syslog?) and integrity (Aide, Samhain, Tripwire, Chkrootkit, COPS, Tiger, lsat, whatever else). And if you have got a clue which box it is, but not *what* it is running, you could tcpdump everything from/to the box for starters, then parse the tcpdumps tru Snort.

Last edited by unSpawn; 03-11-2003 at 08:14 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
having a rough time with wireless on 64bit suse J--Lew Linux - Wireless Networking 1 11-10-2005 01:18 AM
finding a rough go with eth0 and via_rhine static ip nephish Arch 4 10-12-2005 08:53 PM
rough MySQL size calculations? benbroad Linux - Software 2 12-02-2004 06:01 AM
GRUB = bootloader, a rough tutorial aus9 Linux - Software 11 10-01-2004 09:39 AM
Mplayer has been giving me a rough time AekaGSR Linux - Newbie 4 06-13-2003 07:19 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 03:51 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration