LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 07-18-2011, 07:03 AM   #1
Konphine
Member
 
Registered: Jul 2011
Location: Phoenix, New York
Distribution: Slackware 13.37
Posts: 376

Rep: Reputation: 11
Protecting Slackware


Hello,

I know Slackware probably doesn't require too much protection from viruses or spyware, but I'm wondering if there's anything I can do to help protect it (other than Common Sense).

I ask this for 2 reasons:

1. I'm Paranoid
2. Every now and then I mistype a website I go to and it takes me to a completely different website which frightens me because of my paranoia.

So is there anything I can do to help protect Slackware, and in the rare case I get a virus is there a way to remove it directly?

Is it also possible to use Slackware (currently Master drive) to remove a virus on Windows (slave drive)?
 
Old 07-18-2011, 07:07 AM   #2
repo
LQ 5k Club
 
Registered: May 2001
Location: Belgium
Distribution: Arch
Posts: 8,529

Rep: Reputation: 899Reputation: 899Reputation: 899Reputation: 899Reputation: 899Reputation: 899Reputation: 899
Take a look at
http://www.slackbook.org/html/security.html
http://www.chkrootkit.org/

Kind regards
 
1 members found this post helpful.
Old 07-18-2011, 07:13 AM   #3
Konphine
Member
 
Registered: Jul 2011
Location: Phoenix, New York
Distribution: Slackware 13.37
Posts: 376

Original Poster
Rep: Reputation: 11
Thank you. ^^
 
Old 07-18-2011, 07:36 AM   #4
Konphine
Member
 
Registered: Jul 2011
Location: Phoenix, New York
Distribution: Slackware 13.37
Posts: 376

Original Poster
Rep: Reputation: 11
Okay, for those who did see what this post actually was, I fixed it but I have another quick question about chkrootkit. After using it, I came out with this:

Quote:
Searching for suspect PHP files...
/tmp/SBo/package-wxPython/usr/lib64/python2.6/site-packages/wx-2.8-gtk2-unicode/wx/tools/Editra/tests/syntax/php.php
/tmp/SBo/wxPython-src-2.8.11.0/wxPython/wx/tools/Editra/tests/syntax/php.php
Does this mean it's infected, or was it just the file it was checking?

Also, if a file wasn't executed and therefore not testable, should I be worried?

Last edited by Konphine; 07-18-2011 at 07:45 AM.
 
Old 07-18-2011, 07:43 AM   #5
sycamorex
LQ Veteran
 
Registered: Nov 2005
Location: London
Distribution: Slackware64-current
Posts: 5,836
Blog Entries: 1

Rep: Reputation: 1251Reputation: 1251Reputation: 1251Reputation: 1251Reputation: 1251Reputation: 1251Reputation: 1251Reputation: 1251Reputation: 1251
Quote:
Originally Posted by Konphine View Post
When I try installing chkrootkit I get:



But chkrootkit-0.49 is in the folder "chkrootkit" where the .SlackBuild file is.

Any idea what's going on (or know another way to install it? ^^)
You can use sbopkg to install it.
http://sbopkg.org/
 
1 members found this post helpful.
Old 07-18-2011, 08:36 AM   #6
hitest
Guru
 
Registered: Mar 2004
Location: Canada
Distribution: Void, Debian, Slackware
Posts: 7,342

Rep: Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746
Another good tool you can use is rkhunter to see if you've picked up any root kits.

http://slackbuilds.org/repository/13...stem/rkhunter/

Use slackpkg to keep your unit up to date with the latest slackware security patches. Also, having a firewall is a good idea.

http://connie.slackware.com/~alien/efg/

Last edited by hitest; 07-18-2011 at 08:48 AM. Reason: Addition
 
1 members found this post helpful.
Old 07-18-2011, 09:21 AM   #7
Konphine
Member
 
Registered: Jul 2011
Location: Phoenix, New York
Distribution: Slackware 13.37
Posts: 376

Original Poster
Rep: Reputation: 11
Thanks hitest.

Quote:
Use slackpkg to keep your unit up to date with the latest slackware security patches. Also, having a firewall is a good idea.

http://connie.slackware.com/~alien/efg/
I've actually tried this, but it didn't produce a text document as it says it does. It just took me back to the top of the page.

Last edited by Konphine; 07-18-2011 at 09:24 AM.
 
Old 07-18-2011, 09:49 AM   #8
hitest
Guru
 
Registered: Mar 2004
Location: Canada
Distribution: Void, Debian, Slackware
Posts: 7,342

Rep: Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746
Quote:
Originally Posted by Konphine View Post
Thanks hitest.



I've actually tried this, but it didn't produce a text document as it says it does. It just took me back to the top of the page.
That's odd. I just tried Eric's page and it works just fine.

1. Select DHCP or static IP (enter IP address if static IP selected.
2. Select Single system and use IRC if you use that protocol.
3. Click on the Generate firewall button.

Then a new web page will open with the firewall script. Copy and paste that script into a blank text document. Save as rc.firewall. Then as root make that script executable.
# chmod +x rc.firewall

Put that script into /etc/rc.d

# cp rc.firewall /etc/rc.d

Start-up your firewall with:

# /etc/rc.d/rc.firewall start

Last edited by hitest; 07-18-2011 at 09:51 AM.
 
1 members found this post helpful.
Old 07-18-2011, 09:56 AM   #9
Konphine
Member
 
Registered: Jul 2011
Location: Phoenix, New York
Distribution: Slackware 13.37
Posts: 376

Original Poster
Rep: Reputation: 11
Oh okay, I see. I didn't put in my IP address lol. Thank you again.

One final question: Doesn't chkrootkit also look for root kits? Which, if it does, what purpose would I have with rkhunter?

Last edited by Konphine; 07-18-2011 at 09:58 AM.
 
Old 07-18-2011, 10:05 AM   #10
hitest
Guru
 
Registered: Mar 2004
Location: Canada
Distribution: Void, Debian, Slackware
Posts: 7,342

Rep: Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746
Quote:
Originally Posted by Konphine View Post
Oh okay, I see. I didn't put in my IP address lol. Thank you again.

One final question: Doesn't chkrootkit also look for root kits? Which, if it does, what purpose would I have with rkhunter?
You're welcome.
Yes, chkrootkit also checks for rootkits. It can't hurt to have more than one security utility in my opinion (another layer of protection).
 
Old 07-18-2011, 10:08 AM   #11
Konphine
Member
 
Registered: Jul 2011
Location: Phoenix, New York
Distribution: Slackware 13.37
Posts: 376

Original Poster
Rep: Reputation: 11
Oh, this is the last thing (primarily because it was lost in our posts):

Quote:
Searching for suspect PHP files...
/tmp/SBo/package-wxPython/usr/lib64/python2.6/site-packages/wx-2.8-gtk2-unicode/wx/tools/Editra/tests/syntax/php.php
/tmp/SBo/wxPython-src-2.8.11.0/wxPython/wx/tools/Editra/tests/syntax/php.php
I asked if this means it's infected or not since this was my first time using chkrootkit. Also if it says it wasn't scanned because something wasn't executable, does that also mean that program/file is infected too?

Last edited by Konphine; 07-18-2011 at 10:38 AM.
 
Old 07-18-2011, 12:29 PM   #12
Konphine
Member
 
Registered: Jul 2011
Location: Phoenix, New York
Distribution: Slackware 13.37
Posts: 376

Original Poster
Rep: Reputation: 11
Does anybody know? ^^ It's important to the security of my computer. ^^
 
Old 07-18-2011, 12:54 PM   #13
tekhead2
Member
 
Registered: Apr 2004
Distribution: slackware/FreeBSD/Vector
Posts: 291

Rep: Reputation: 52
I imagine the fact that there is a PHP file in the /tmp directory that it looks like something malicious, the /tmp directory is a notorious directory for dropping code and other exploits as it's usually configured with lax permissions and is usually the entry point for many local attacks. I could be wrong, but knowing rootkits and how they work, I imagine that since the code is related to sbopkg and is calling tgz and other archive file types, it just looks suspicious.
 
Old 07-18-2011, 01:02 PM   #14
Konphine
Member
 
Registered: Jul 2011
Location: Phoenix, New York
Distribution: Slackware 13.37
Posts: 376

Original Poster
Rep: Reputation: 11
I'm worried whether I should delete directly or not.
 
Old 07-18-2011, 01:05 PM   #15
hitest
Guru
 
Registered: Mar 2004
Location: Canada
Distribution: Void, Debian, Slackware
Posts: 7,342

Rep: Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746
Try scanning your unit with rkhunter and see if it finds anything odd. After you've installed rkhunter it runs on the command line from /usr/bin

Update rkhunter as root by

# rkhunter --update

then scan your system by

# rkhunter --checkall
 
2 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Protecting a database jasonswett Linux - Security 15 10-04-2010 03:16 AM
protecting files andystanfordjason Linux - Security 3 12-31-2006 11:29 AM
Protecting a Laptop? flamesrock Linux - Hardware 4 09-11-2005 10:08 PM
Protecting data... Dee-ehn Linux - General 5 06-09-2005 04:41 PM
is slackware protecting me? shanenin Slackware 1 10-19-2003 09:28 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 11:45 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration