LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-06-2001, 09:16 PM   #1
vcheah
Member
 
Registered: Nov 2001
Distribution: redhat 8.0
Posts: 110

Rep: Reputation: 15
Any attack?


I knew that there is a way to check whether my box being attack or just living happyly. BUt where can i check that?
 
Old 12-07-2001, 01:26 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
(Lets leave out the OSI model layer naming scheme for simplicity's sake)

If you didn't take any measures to protect your box, possible "evidence" of a *network based attack* can be found in the system logs, and the logs of applications running at the time of the attack. They're in /var/log by default.

If you did add chkrootkit, from chkrootkit.org, tripwire,Aide or Samhain (see freshmeat.net), or are using a package management tool that uses GPG signatures or MD5-sums, it can scan your filesystems and report for *filesystem data alterations* that could be the evidence of an attack.

If you did add a firewall (ipf, ipfwadm, ipchains or netfilter/iptables), and set up the rules to dissallow access for certain types of traffic/packet flags set, and added logging, then their logging of *network traffic* is in /var/log too.

If you did add some IDS capability like Snort (snort.org) (don't use portsentry) it can filter and report on what kind of *network traffic anomalies* has happened.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
What attack could this be??? darrel Linux - Security 10 02-26-2005 10:10 PM
What to do during an attack? revenant Linux - Security 9 04-02-2004 12:18 AM
hacker attack? zetsui Linux - General 4 08-04-2003 06:03 AM
Sendmail Attack m0rl0ck Linux - Security 4 07-04-2003 04:08 AM
Help I am UNDER ATTACK... needamiracle Linux - Security 28 04-22-2003 12:06 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:32 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration