LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-24-2014, 06:18 PM   #1
umbloaded
Member
 
Registered: Apr 2013
Posts: 38

Rep: Reputation: Disabled
server log


Hello,
I need a way to find how hackers sometime get into a website and change files, what would you suggest me ?

Thank you
 
Old 07-24-2014, 10:11 PM   #2
kirukan
Senior Member
 
Registered: Jun 2008
Location: Eelam
Distribution: Redhat, Solaris, Suse
Posts: 1,278

Rep: Reputation: 148Reputation: 148
I never used tools like Snort for intrusion detection, i hope this will be helpful to you.
https://www.snort.org/
go ahead and understand it.
 
Old 07-24-2014, 10:29 PM   #3
John VV
LQ Muse
 
Registered: Aug 2005
Location: A2 area Mi.
Posts: 17,624

Rep: Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651
if the "cracker" ( not hacker ) dose there job right, you will almost NEVER know they are there .

now "script kiddies" on the other hand , they do leave evidence all over the place .

and Snort WILL show them .
 
Old 07-25-2014, 01:50 AM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by umbloaded View Post
I need a way to find how hackers sometime get into a website and change files, what would you suggest me ?
For what purpose if I may ask? If files changed then getting the hashes from the original software and running them against 'md5deep -r -x' could be a quick start. But if this is thought to be part of "regular maintenance" then I suggest you change your strategy to a more active one and guard against having old or vulnerable installed software versions first. As in combating the cause, not just symptoms.
 
2 members found this post helpful.
Old 07-29-2014, 09:21 AM   #5
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,634

Rep: Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965
Quote:
Originally Posted by umbloaded View Post
Hello,
I need a way to find how hackers sometime get into a website and change files, what would you suggest me ?
Absolutely agree with unSpawn. The best suggestion would be for you to properly secure your server/network. Snort is a good tool, but you have to use it as part of a larger strategy. Firewalls, DMZ's, etc., all need to play a part, along with proper systems security.

Think of it as a house; if you leave the doors unlocked and the windows wide open, it's VERY hard to see how someone got in. Lock things up, and put an alarm on, you can EASILY see a broken window, know which door was opened, etc. This is no different...the more layers between your server and the Internet, the harder it is..and each layer will get you traces on how things were broken.

Last edited by TB0ne; 07-29-2014 at 09:24 AM.
 
Old 07-30-2014, 05:47 AM   #6
umbloaded
Member
 
Registered: Apr 2013
Posts: 38

Original Poster
Rep: Reputation: Disabled
I think the problem relies on the web application code. There must be some bug and checking all parameters would be difficult due it is a large application
 
Old 07-30-2014, 08:38 AM   #7
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,634

Rep: Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965
Quote:
Originally Posted by umbloaded View Post
I think the problem relies on the web application code. There must be some bug and checking all parameters would be difficult due it is a large application
This is an absolutely HORRIBLE approach to this problem...you're essentially saying:
  • You don't know what the problem(s) are
  • You don't know WHERE the problem(s) are
  • Since it's a 'large application', it's alot of effort to check, and you don't seem to plan on checking it.
Please, don't wonder why your site has problems. If you are serious about securing it, then you have one option: work hard, find the holes, bugs, and vulnerabilities, and FIX THEM. That's the job of a systems administrator...if you're also the web programmer, then you have to fix THAT too.
 
1 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
In Apache server, How to change log file location and log format for access log fil? since1993 Linux - Server 1 08-19-2009 04:14 PM
the significance and name of the 5th column of /var/log/auth.log (ubuntu server)? CoffeeKing!!! Linux - Security 4 02-05-2009 07:32 AM
Can Samhain log my entries in /var/log/secure and /var/log/mesage to a central server abefroman Linux - Software 2 04-13-2008 04:13 PM
Bash script for server log (namely var/log/messages) tenaciousbob Programming 17 05-24-2007 10:43 AM
How to log conversation between server in /var/log/messages? juris Linux - Software 1 11-23-2004 09:54 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:45 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration