LinuxQuestions.org

LinuxQuestions.org (/questions/)
-   SUSE / openSUSE (https://www.linuxquestions.org/questions/suse-opensuse-60/)
-   -   "Secret Cookie" (https://www.linuxquestions.org/questions/suse-opensuse-60/secret-cookie-485176/)

raysr 09-20-2006 12:23 AM

"Secret Cookie"
 
I don't know if one issue has anything to do with the other but here's my problem. Last week I was looking through e-bay and my system monitor on the toolbar ran up into the yellow and the box took off like a race car. I unplugged the phone line as fast as I could and the box ran for a few more seconds and slowed back to normal. This has happened about three times now, only on Suse, drive hda. Xandros hdb hasn't been affected.
So I started looking around in the "tmp" file and under /tmp/ksocket-me there's a file called "Secret Cookie". It has a number in it about 13 characters. I deleted it and tried to reproduce it. I could not. Except when I rebooted. Then it would show up again. I have a firewall, Yast, and guarddog. GRC says I'm stealthed and so does PC Flank.
Any ideas as to what this is all about?

zhangmaike 09-20-2006 01:42 AM

The secret-cookie thing is completely normal and unrelated to the problem that you're noticing. See this thread: http://www.linuxquestions.org/questi...d.php?t=465098
In that thread is a link to another thread, which explains the secret-cookie as a normal authentication token.

As for the problem... what do you mean that the "system monitor on the toolbar ran up into the yellow and the box took off like a race car"? What does yellow indicate in your system monitor? What is racing about your computer? Disk usage? CPU?

Have you been able to purposely reproduce the "racing" problem?

raylhm 09-20-2006 02:16 AM

CPU usage-yes, yellow. Box clicking away like it was booting up(race car). Thanks for the link and the reply. I don't have to worry about the cookie anyway. Yeah, once I was just reading my e-mail and it took off as described. None of these things may not be connected, it's just odd when the cpu jumps up for no reason.

Spudley 09-20-2006 06:07 AM

It could be your cron jobs starting up (cron being a timing system to trigger regular tasks automatically).

Even if you haven't got any tasks of your own in your crontab, there are likely to be some at system level, and it's possible they may be what you're seeing.

If you've got KDE System Guard running, or top, you should be able to see quite easily what the processes are that are causing the CPU usage to spike.

JZL240I-U 09-20-2006 08:01 AM

Check your crontab for cronjobs (plus: cron.hourly, cron.daily, cron.weekly etc.). Maybe you're starting something on autopilot there.

raylhm 09-22-2006 02:01 AM

Thanks for the replies. I have another question. I've been messing around with my firewall, Suse and I had guarddog. The Suse firewall started giving me an error saying there was another firewall running and I couldn't configure it until I got rid of the other one(although I had before) so I deleted guarddog and nothing changed, it still says there's another firewall running. Went to GRC and I'm still stealthed. What's going on? All I had installed was guarddog and Suse. I get alot of iptable eroors on boot also. Any idea what's happened?..........I just rebooted and all is A-OK now. I've got a DSL/cable router with a firewall so I'm probably OK anyhow.

JZL240I-U 09-22-2006 03:20 AM

Deleting a software is not all. A firewall will run in the background (or as daemon) as an independent process. You have to shut that down explicitly -- which you did by rebooting.

raylhm 10-02-2006 09:31 PM

If anyone is still following this thread, I got a letter from Verizon today saying that "someone" may have gained access or attempted to gain access to my customer account through verizon.com website w/o my authorization. "Although it 'appears' no usable information was obained we are nevertheless taking additional measures to protect your account". I haven't talked to them yet but I'm wondering if the problem was on my end or theirs. I'm stealthed everywhere I check plus I have a cable router with a firewall.

JZL240I-U 10-04-2006 01:40 AM

So. Well, if you get more information on this a brief post would be appreciated. Regards :).

raylhm 10-06-2006 12:25 AM

I called Verizon the next day and they asked if I ever paid my bill online at "Verizon.net". I told them I did not. They asked me if I ever visited "Verizon.net" and I said I probably had. They said to disregard the letter they sent because it was some information mining on people who pay their bill online there. If I hadn't paid there I wasn't one who was attacked. They got me because I visited there.
Scared the SHIT out of me before I called them. I still don't feel to good about my security, even though everywhere I test says I'm stealthed.

JZL240I-U 10-06-2006 01:25 AM

Well something caused the abnormal behaviour of your box, and not on the server side / verizon side. Maybe you'd better post your firewall rules in the security forum and ask for opinions there.

raylhm 10-09-2006 12:31 AM

Is there a command to bring up how I have the SuseFirewall2 set-up?

JZL240I-U 10-09-2006 02:29 AM

There should be a iptables.config (?) file (probably somewhere under /etc, just search for it). That should hold your rule set.

raylhm 10-10-2006 12:42 AM

I couldn't find "iptables.config" in /etc so I seached it and it never showed up. I've run AVG Free on every file I can and it has found nothing.

JZL240I-U 10-10-2006 01:25 AM

when you search just for "*iptable*" without the ""'s, what do you get?


All times are GMT -5. The time now is 02:56 PM.