LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-26-2004, 04:12 PM   #1
robertn
Member
 
Registered: Mar 2004
Location: mid-atlantic
Distribution: mandrake 9.1 rc2
Posts: 43

Rep: Reputation: 15
Mozilla/Google interfaced hacked


hello
I was trying to set up a firewall and made the mistake of using Mozilla when I was logged in as root on a console (or at least I think this is what happend). I was probing myself using "nmap -vv localhost, netstat -lnp, route, ping" and so on. Anyway, before I got the Iptables up and running, I saw that when I mouse clicked on the Mozilla search window, the google location was redirected to a porn site and all kinds of fast moving messages were observed by me as it happened. "...spy.com.org or something....." and so on.

As this is an experimental partition to a dual boot Windows98 SE install, I just popped the Mandrake 9.1 RC2 cooker cd-rom into the bay and rebooted and immediately reformatted the 4 partitions that I made on the Linux side and reinstalled the system. I noticed that this installer makes an "old linux" option available on lilo and presumably this is the system that I just tried to get rid of.

The question is......Am I compromised?; How would I know? I am on-line now with the new setup (including a rudimentary iptables firewall that blocks all ports) and using Mozilla and running "top" on a console shows everything pretty normal. Is there anything that I should do. I intend to next go to Mandrake and download security and other updates. Is there any place I should go for a test of my system?

thanks for any guiding or suggestions. robertn

Last edited by robertn; 03-26-2004 at 04:13 PM.
 
Old 03-26-2004, 05:02 PM   #2
zackarya
Member
 
Registered: Jul 2003
Distribution: OpenSuse 10, Debian
Posts: 152

Rep: Reputation: 30
robertn, I don't think that you have anything to worry about. Sometimes webpages can (depending on various things) change certain settings in your browser, ie. changing your homepage to pr0n or something. So that is most likely what happened. However, since you went through the effort of formatting and re-installing, you don't have anything to worry about. In the future I would not suggest such a radical solution as the first step. Normally, the only time you would format and re-install is as the last resort. Also note, even though you had not yet set up your firewall, since you initiated the connection by asking mozilla to access some web page, the firewall would not stop this anyway. The best thing you can do to keep your system secure is to update regularly. If your really paranoid, you could do a fresh install, get checksums for all you system files, also backup all your system files on a completly different physical device that is not on the network and if you think something strange is going on, you can compare your system file checksums and if something does not match, replace the file or files with your backup files. Of course you have to update your checksums and backup files whenever a legitamate update changes your system files. There are some software packages that helps to automate this process. I hope that this helps you.
 
Old 03-26-2004, 10:49 PM   #3
witeshark
Member
 
Registered: Jan 2004
Location: Miami FL
Distribution: Mac OS X 10.4.11 Ubuntu 12.04 LTS
Posts: 429

Rep: Reputation: 30
And in the future please never be on line as root
 
Old 03-27-2004, 12:00 AM   #4
robertn
Member
 
Registered: Mar 2004
Location: mid-atlantic
Distribution: mandrake 9.1 rc2
Posts: 43

Original Poster
Rep: Reputation: 15
Thumbs up

Thanks for the replies; I feel better. I am still setting up this old machine and experimenting. After I am satisfied with the network/internet interface, I intend to add either a CD-RW drive or a USB external device for backing up the systems. I will investigate the checksums utility then.

Also copy the online as root warning; I will follow. Right at this moment, I am considering changing ISP and I was considering reinstalling anyway in order to reconfigure my partitions more advantageously, so I just used the Google redirected to Porn as a convenient reason to do it now.

By the way, I just noticed that my KPPP utility is owned by root and although I called it from KDE desktop logged in as user , the output of "ps -aux" shows that it apparently executes as root. Now this only gets me as far as my ISP and I am behind the ISP's firewall, but the /usr/bin/mozilla executable is also a root owned executable. Is this right? I am sure it must be since people who know designed it, but I am just wondering? As you can see, I am pretty unsure of myself and have more questions than answers.

thanks again, robertn

Last edited by robertn; 03-27-2004 at 12:18 AM.
 
Old 03-27-2004, 05:04 PM   #5
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
Since Google is the most popular search engine, there are a lot of attempts at DNS poisoning to redirect to other sites, and also a lot of malicious scripts on websites that try to change your browser settings or install plugins. If you didn't have a firewall setup, there's a fairly decent chance that you were the victim of DNS poisoning.

This is an excellent illustration of why you should secure your box *BEFORE* you connect it to the 'net, instead of the other way around.
 
Old 03-27-2004, 09:06 PM   #6
robertn
Member
 
Registered: Mar 2004
Location: mid-atlantic
Distribution: mandrake 9.1 rc2
Posts: 43

Original Poster
Rep: Reputation: 15
Thumbs up thankyou & followup update

I do appreciate the scolding and the interest. I now have two basic firewall scripts functional. The first I got from the Security Quick-Start HOWTO v1.1 included with the Mandrake 9.1 rc2 which blocks everything and the second from the wiki.org site affiliated with this site. This one allows SSH from port 20 and FTP from port 21. Both are simple enough that a new user can understand how they work.

Today, I fired up #2 firewall and used the update utility in the Mandrake Control Center GUI at the Software Tab and the Update button therein. It made a valiant download of almost 6 Mbytes (according to the little "led" display connection utility in the system tray) and then automatically pulled up the urpmi/rpm GUI and apparently checked for updateable packages. It then informed me that there were none or that I had already accomplished available upgrades.

This also has me wondering since this is the first time that I have tried to use an FTP mirror site to download anything. Am I really up to date with available security patches? I bought these install disks from the famous "Cheapbytes" site. Or is it perhaps that 9.1 is not supported anymore?

OH well; I feel like I am making progress anyway. Thanks again

robertn
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Floppy drive interfaced tape drive in Slackware isolationist Linux - Hardware 6 02-13-2006 05:54 AM
Mozilla Thunderbird Atom and Google xtracto Linux - Software 0 12-08-2004 10:55 AM
mozilla 1.4 crashes on google search SerfurJ Linux - Software 1 11-20-2003 10:40 AM
newbie, problem installing google bar for Mozilla vladi Linux - Software 8 08-23-2003 08:46 PM
Dorons Google Toolbar form Mozilla Gman22 Linux - Software 2 08-18-2003 05:08 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:19 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration