LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-16-2011, 09:48 PM   #16
warnold
LQ Newbie
 
Registered: Jan 2008
Posts: 18

Original Poster
Rep: Reputation: 0

Quote:
Originally Posted by corp769 View Post
Show us proof.
All I know is what I was seeing on my system. Only became aware of something going on when I went to mount a usb device from a terminal window. That is when I first saw by accident and paid attention to
a different root prompt. Seeing that, I opened a setroubleshoot window and saw in red at the bottom of its window that the server was disabled. I wrote
down all that I tried & what was observed. Today I
physically took my pc to another physical location &
knowing that the person uses a different isp-dsl provider and none of the previous things took place.
Was on the internet for at least 1 to 1.5 hrs. Opened & observed the setroubleshoot window, no issues. Brought my system home, booted it, issues
return. Nothing is being logged. I am not trying to be a pain, I was just reporting what I observed on my
system. I do not have the unix expierience to dream this up. How I know about the keystrokes being mapped, (|'), is from the old days of Digital's vax/vms .. The |' prompt only shows when giving a log-in & password while going to certain popular
web-sites.
That's all. I will simply close this, and wait till others start to see things on their linux systems.
 
Old 02-16-2011, 10:49 PM   #17
corp769
LQ Guru
 
Registered: Apr 2005
Location: /dev/null
Posts: 5,818

Rep: Reputation: 1007Reputation: 1007Reputation: 1007Reputation: 1007Reputation: 1007Reputation: 1007Reputation: 1007Reputation: 1007
Roger that. If it persists, let us know. Myself, including many others, will definitely be willing to assist....
 
Old 02-19-2011, 06:32 PM   #18
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by warnold View Post
All I know is what I was seeing on my system. (..) I was just reporting what I observed on my system.
If you would have posted log excerpts and error messages then you would have reported an issue.
Instead you tried to interpret what you thought you were seeing and talking about it.


Quote:
Originally Posted by warnold View Post
Nothing is being logged.
That simply is not true unless 0) there is something amiss or 1) you don't know what to look for or where.

If you want to get to the bottom of this: Centos comes with standard syslog enabled so 'grep -v ^.*# /etc/syslog.conf | awk '/log\// {print $NF}';' (or '/usr/sbin/lsof -Pwln +D/var/log|awk '{print $NF}'|sort -u') gives you the logfiles to look for. A more efficient way would be to run your logs through 'logwatch' as its report makes it easier to pinpoint issues. Since you mention Setroubleshootd (see /var/log/setroubleshoot/setroubleshootd.log), if the audit service is enabled then your next stop is /var/log/audit/audit.log (else it'll log in /var/log/messages). An efficient way to check if there's issues is to run 'audit2allow < /var/log/audit/audit.log'. If this outputs anything there's probably things to correct. None of this requires hardcore Linux knowledge as the information is at your fingertips: Red Hat comes with extensive installation and maintenance documentation and Centos has its own Wiki.


Talking about Centos: please do not use obsolete releases. Centos 5.5 is the current release. By updating your machine all bugs and security issues that have been fixed in the current release become available to you and this may include SELinux policy fixes.
 
1 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Prevent setroubleshoot from cluttering syslogs? larold Linux - Enterprise 1 07-24-2010 05:07 PM
Printers become disabled tdevogel Linux - Newbie 0 12-27-2007 04:06 PM
How can I disabled SELinux? abefroman Linux - Kernel 3 09-17-2006 10:22 AM
su to disabled accounts? sat86 Linux - Security 1 01-24-2005 06:05 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:55 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration