LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-03-2007, 09:42 PM   #1
otacon 14112
Member
 
Registered: Apr 2004
Location: /
Distribution: ubuntu (gutsy)
Posts: 46

Rep: Reputation: 15
Can intruders hide from who and w?


I am wanting to beef up my security. I already do regular who and w checks, but something tells me this really isn't much. I was wondering if these are even any way to check to see if you're being compromised. I don't know how a person would hide from them; I think they'd have to log in as SOMEBODY at some point...but I really am ignorant on security.

Thanks,
otacon
 
Old 04-03-2007, 10:27 PM   #2
jiml8
Senior Member
 
Registered: Sep 2003
Posts: 3,171

Rep: Reputation: 116Reputation: 116
If someone has compromised your machine, they could replace the who command with their own version, which would report on everyone EXCEPT them.

So, yes, they could hide from you in that regard. Of course, you'd still find them if you kept a close eye on /etc/passwd and /etc/shadow..

Security is a journey, not a destination. There are many things you can do, and (depending on what your machine is used for) there are many things you need to do, and pretty much all of it is covered in this forum in one place or another. Look around, google a lot, and generally learn. When you have specific questions feel free to ask; someone'll answer.

Last edited by jiml8; 04-03-2007 at 10:28 PM.
 
Old 04-03-2007, 11:54 PM   #3
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
It's also very common to see the files ((/var/log/wtmp and /var/log/utmp) that last and who use to display login info get wiped/replaced as well. Chkrootkit and I believe rkhunter both do checks for wtmp/utmp modification, so I would highly recommend one of those as well. Last time I used Mandriva it was still called Mandrake :-P but I found the msec tool was fairly effective at tightening system security, especially at higher security levels. Though it could be a bit of a pain at times and for some reason the great documentation they had disappeared as well.

Lastly, there is no real perfect all-in-one security solution. It's really a process that requires multiple levels (application hardening, system hardening, pro-active measures, consistent updating, vigilance). If you are interested in improving these areas, one of the best places to get started is unSpawn's security references thread at the top of the forum. Start at the more general hardening guides and work your way out from there.
 
Old 04-04-2007, 12:09 AM   #4
otacon 14112
Member
 
Registered: Apr 2004
Location: /
Distribution: ubuntu (gutsy)
Posts: 46

Original Poster
Rep: Reputation: 15
Those were some really good tips, thanks guys. I'm thirsty for more. My friend tells me there is a book at the book store about intrusion detection which I plan on buying. I am willing to learn as much as possible.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Detecting Intruders with IPCop LXer Syndicated Linux News 0 10-09-2006 07:03 AM
How to secure the server and how to track down intruders? depam Linux - Security 5 07-01-2006 03:32 PM
susefirewall2 and seeing intruders oily_rags SUSE / openSUSE 12 12-17-2005 12:22 AM
tracking intruders bishal Linux - Security 1 08-14-2004 07:12 AM
Microsoft’s network is hacked - Intruders believed to have stolen code for software jeremy General 3 11-26-2000 08:21 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:54 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration