LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-31-2002, 07:10 PM   #1
Scotty2435
Member
 
Registered: Dec 2001
Location: Waco, Texas USA
Distribution: Redhat 7.1
Posts: 232

Rep: Reputation: 30
Real threat or just paranoia


Today when I came home to my linux box and booted the syslog came up as failed on startup. When I try to run top it gives me an error about a missing file. My linux box had been running default red hat 7.1 ftp telnet ssh and http servers with no firewall protection. Also when I try to start KDE the task bar doesn't load. The last message in /var/log/messages is of an annonymous ftp login using a very fake sounding email.

So did someone get on my linux box or am I just overreacting. Thanks in advance.
 
Old 01-31-2002, 08:13 PM   #2
Scotty2435
Member
 
Registered: Dec 2001
Location: Waco, Texas USA
Distribution: Redhat 7.1
Posts: 232

Original Poster
Rep: Reputation: 30
i put my router firewall up again and disabled annonymous ftp access in the ftp users file. Anyone know how I can fix top, kde, and get logging going again. I'm going to take security much more seriously now.
 
Old 01-31-2002, 08:14 PM   #3
drjimstuckinwin
Member
 
Registered: Mar 2001
Location: Manchester UK
Distribution: Mainly Fedora
Posts: 496

Rep: Reputation: 30
Whilst missing panel bits and startup problems are not a new concept, particularly when you accidentally pull the power lead when you get up from your chair (!), the anonymous ftp screams hack. Get the box offline if you can, and run chkrootkit, also what commands do you see if you use the cursor up keys in root/user accounts. You'll probably have to reinstall. A firewall would be a very good idea.
Jim
 
Old 01-31-2002, 08:35 PM   #4
Scotty2435
Member
 
Registered: Dec 2001
Location: Waco, Texas USA
Distribution: Redhat 7.1
Posts: 232

Original Poster
Rep: Reputation: 30
on the root accounts the up and down arrow keys only produce my stuff. The box is down now and is booted into windows
 
Old 01-31-2002, 09:43 PM   #5
Scotty2435
Member
 
Registered: Dec 2001
Location: Waco, Texas USA
Distribution: Redhat 7.1
Posts: 232

Original Poster
Rep: Reputation: 30
do you know how I can get top, the system logger and kde working again. Thanks
 
Old 01-31-2002, 09:51 PM   #6
drjimstuckinwin
Member
 
Registered: Mar 2001
Location: Manchester UK
Distribution: Mainly Fedora
Posts: 496

Rep: Reputation: 30
It's possible you could re-install the relevant bits and be OK, but you should be afraid. A reinstall is safest, have you got any critical data on the system? Did you install tripwire? I did, and always wondered why, it sends me mail whenever I redo the kernel, which is very irritating, but when I'm worried I've been hacked it doesn't, therefore I've "probably" not been.
Jim
 
Old 01-31-2002, 11:00 PM   #7
Scotty2435
Member
 
Registered: Dec 2001
Location: Waco, Texas USA
Distribution: Redhat 7.1
Posts: 232

Original Poster
Rep: Reputation: 30
i think I will reinstall I've had to do it twice now so it doesn't take me long to get everything back in shape.
 
Old 02-01-2002, 02:52 PM   #8
Scotty2435
Member
 
Registered: Dec 2001
Location: Waco, Texas USA
Distribution: Redhat 7.1
Posts: 232

Original Poster
Rep: Reputation: 30
ok I'm reinstalled how can I keep this kind of thing from happening again. How can I disable anonymous ftp. Thanks.
 
Old 02-01-2002, 11:20 PM   #9
Scotty2435
Member
 
Registered: Dec 2001
Location: Waco, Texas USA
Distribution: Redhat 7.1
Posts: 232

Original Poster
Rep: Reputation: 30
anyone have some advice
 
Old 02-02-2002, 02:58 AM   #10
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
- remove the anonftp package if installed,
- remove /etc/{passwd,group,shadow,ftpusers} entries for user FTP, associated with anonymous ftp account
- find out what the base address is the ftpd chroot's to to allow anon ftp access, and remove all authentication files, binaries, devices and libraries from where the ftp account is
- review your configs and access lists in /etc(/fptd) so user FTP isn't listed, and anything referring to class anonymous is deleted.
- restart ftpd and check logging in, check ftpd log and syslog for errors.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Newb Paranoia markopolox Debian 8 04-13-2004 11:03 PM
Portage paranoia jiggywiggy Linux - Software 0 02-15-2004 05:56 PM
Paranoia due to lack of knowledge downinthemine Linux - Security 2 12-04-2003 12:37 AM
Real Programmers Real People Real CS Students nakkaya General 5 07-04-2003 02:46 PM
RH 8.0 / Grip / paranoia problem marzagao Linux - Hardware 1 02-08-2003 09:13 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:04 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration