LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-26-2006, 03:43 PM   #1
BinJajer
Member
 
Registered: Sep 2005
Location: Warsaw, Poland
Distribution: Slackware 10.2, Caldera OpenLinux 3.1, Corel Linux (Thanks xhi!), Debian GNU/HURD etc...
Posts: 296
Blog Entries: 1

Rep: Reputation: 30
CLose one -- desktop almost compromised.


Jesus, I got almost compromised a few days ago. Fortunate I had chrootkit installed, because I suddenly had root login on ttyp0.
I quickly cut that one off, but a few of the text files in /root contained only " --||--". Must have been one of those damn script kiddies... Cause who would care to break into a desktop?!
 
Old 01-26-2006, 05:04 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
I got almost compromised a few days ago. Fortunate I had chrootkit installed, because I suddenly had root login on ttyp0.
That is not a logical conclusion: if you had an unauthorised root account login your box probably *is* compromised. Did you already start investigating it?


Cause who would care to break into a desktop?!
Because you practically invited them in? Or because Linux is a more versatile and powerful platform?
 
Old 01-26-2006, 05:51 PM   #3
BinJajer
Member
 
Registered: Sep 2005
Location: Warsaw, Poland
Distribution: Slackware 10.2, Caldera OpenLinux 3.1, Corel Linux (Thanks xhi!), Debian GNU/HURD etc...
Posts: 296

Original Poster
Blog Entries: 1

Rep: Reputation: 30
Yes, I did investigate. Pretty much nothing... but at least I know and have fixed the security issue. I don't think that a man who encrypts his hd, mixes is nine-symbol password with blf and is behind a firewall invites every passing kiddie. And, man -- think what you are saying. Both BSD and Linux are secure and versatile. Come on, spread linux advocacy, but don't be a fanatic. Say, OpenBSD. Is there a Linux that is _half_ as secure?
 
Old 01-26-2006, 06:29 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
BTW, this the Linux - Security forum: you may show your leet BSD pissing-contest-fu in the LQ /General dojo.

Last edited by unSpawn; 01-26-2006 at 07:03 PM.
 
Old 01-26-2006, 06:45 PM   #5
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Quote:
Originally Posted by BinJajer
at least I know and have fixed the security issue.
what was the security issue?? how did you fix it??

how do you know they didn't leave any other backdoors, etc?? if they had root your system is pretty much untrustable until you re-install...

Quote:
I don't think that a man who encrypts his hd, mixes is nine-symbol password with blf and is behind a firewall invites every passing kiddie.
disk encryption does absolutely nothing as far as OS exploits are concerened...

Quote:
And, man -- think what you are saying. Both BSD and Linux are secure and versatile. Come on, spread linux advocacy, but don't be a fanatic. Say, OpenBSD. Is there a Linux that is _half_ as secure?
before this thread turns into a pissing contest (i have a feeling that it will), i'd like to remind you that security is a P-R-O-C-E-S-S, not a product... just cuz you install openbsd doesn't make you any more secure than a [insert favorite distro here] linux user... it depends on many factors, like your skills/experience, for example...

Quote:
who would care to break into a desktop?
someone wanting to send-out 3,000 SPAM messages per minute maybe?? or someone wishing to make a nice addition to their botnet, keeping you on standby for their next big DDoS?? the list of "who" is endless...

they need not be after your info, but resources such as bandwidth are very attractive to a lot of people and the worms they give birth to...

Last edited by win32sux; 01-26-2006 at 06:50 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
mplayer 'close all' doesn't close anything allelopath Linux - Software 2 12-08-2005 09:40 AM
Compromised? I can't tell. Chuck23 Linux - Security 11 02-15-2005 07:33 AM
Am I compromised? dripter Linux - Security 5 01-27-2004 12:31 AM
System compromised BruceCadieux Linux - Security 20 09-29-2003 08:24 PM
which ports can i close on a home desktop? all? zerojosh Linux - Security 7 07-06-2003 07:31 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:05 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration