LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-31-2005, 09:54 AM   #1
izquierdista
Member
 
Registered: Mar 2005
Distribution: Ubuntu
Posts: 344

Rep: Reputation: 30
could my computer have been compromised?


I would like to know if my computer has been compromised

today I wanted to change my root password I went to the control center and then I pulled up the edit user menu. I saw two users one was mine

the other user that was listed was AVG

both had the same password. Does AVG mean administrator? am I suppossed to have 2 users even though I am the only user of the computer.

well in any case can any one tell me now to change my root password on SUSE 9.1?
 
Old 03-31-2005, 10:12 AM   #2
mikeyt_333
Member
 
Registered: Jun 2001
Location: Up in the clouds
Distribution: Fedora et al.
Posts: 353

Rep: Reputation: 30
not a suse person, but I'd do it at the command line. Open a terminal window, type "su -" to switch to root, then type "passwd" it will prompt you for a new password, and confirm it etc... What Desktop Manager are you running, that would help me help you do it through the GUI.
 
Old 03-31-2005, 01:34 PM   #3
Krugger
Member
 
Registered: Oct 2004
Posts: 229

Rep: Reputation: 30
I ran suse for a while and I don't remember seeing any AVG user. But check your /etc/passwd and /etc/shadow to see if it is a real user or not.
 
Old 04-01-2005, 07:03 AM   #4
izquierdista
Member
 
Registered: Mar 2005
Distribution: Ubuntu
Posts: 344

Original Poster
Rep: Reputation: 30
Angry

I think that I have been hacked because when I started my computer today I saw a login for the AVG user. When I saw this I went to the control center and erased it. Is this enough to kick him/her off my computer?
 
Old 04-03-2005, 12:04 PM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Erasing an account will make it impossible for someone to gain access through that 'hole', but not impossible if other holes exists.
Besides, by erasing the account you'll disown processes and files which ain't good.

If you mean AVG as in "Anti-Virus Software by Grisoft", did you install their software? If not please:
- reset the shell to /bin/false, /sbin/nologin or whatever inert dummy shell you have
and check your:
- processes for processes owned by that user,
- filesystem for files owned by that user,
- login records (last, lastb, faillog) and system, application and firewall logs for any unusual activity.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
My NTP has been compromised wylie1001 Linux - Networking 4 05-09-2005 07:24 PM
Compromised? I can't tell. Chuck23 Linux - Security 11 02-15-2005 07:33 AM
possibly compromised - what to do? TreeHugger Linux - Security 4 02-04-2005 11:03 PM
Server was compromised, need help Asiana Linux - Security 3 06-02-2004 12:39 PM
Am I compromised? dripter Linux - Security 5 01-27-2004 12:31 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:55 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration