LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 04-22-2005, 04:21 PM   #1
rockwell_001
LQ Newbie
 
Registered: Jun 2004
Posts: 23

Rep: Reputation: 15
Linux backup


Hi all, previously i posted a thread about how to know if the server got hacked, that is because our server was hacked twice in the past 30 days, i think he is the same guy. What happened was he created a guest account and deleted some files. So what i would like to do now is to backup linux machine into an other harddrive(secondary) in the linux box. I wanted to do it in such a way that all the data including root, bootloader(what ever, i guess everything) are backed up to the secondary disk and if the server is hacked, just copy/restore everything into the primary harddisk from the secondary and the system should bootup normally. I dont know if we can do this or not, can you give me some tips regarding this(wheter to write a script and how to write the script).

If you are not clear with my question, can you please reply me and i can put it in an other way. I really need to do this because there are several hack attempts being made from every week.(i know this because i installed logwatch).

Could you please help me out .....
Thanks for your previous replies...
 
Old 04-22-2005, 04:36 PM   #2
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
IMHO, it would be pointless to restore a backup of the system that's getting owned - as it will simply get owned again, cuz you'd be restoring the system and the security hole also.... what you need to do is find the hole the attacker is using and then close it...
 
Old 04-22-2005, 05:09 PM   #3
jimdaworm
Member
 
Registered: Aug 2003
Location: Spain
Distribution: Ubuntu
Posts: 897

Rep: Reputation: 30
I have to agree but once you have a secure install, if you want to back it up have a look at partimage its pretty cool and will same exact images of hole partitions.
 
Old 04-22-2005, 05:28 PM   #4
bigrigdriver
LQ Addict
 
Registered: Jul 2002
Location: East Centra Illinois, USA
Distribution: Debian stable
Posts: 5,908

Rep: Reputation: 356Reputation: 356Reputation: 356Reputation: 356
I find that DAR gives me what I need. Dar allows me to restore one file, one directory, or the entire directory tree. I can backup directories (but not the files within) if I don't care about the files but want to keep the directories. I get approximately 50% compression in my backups. I can specify which files to exclude, which to enclude, which to not try to compress because they're already compressed. The list goes on.
But, as win32sux said, if you don't close the door the hacker is using, you will only keep opening that door for him when you restore a backup.
Get the system to a secure state, then make a backup.
 
Old 04-22-2005, 06:32 PM   #5
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
rockwell_001: also keep in mind that you should never put this type of backup on a secondary disk on the system... that would work fine for a anti-data-loss type of backup (the usual kind of backup), but for a rescue backup you are much better-off using something like partimage, as suggested by jimdaworm above... this way you can put the backup on a different server, or on a cd/dvd with no problems...

if an attacker owns your system, there's nothing preventing them from doing all kinds of modifications to your "backup" on the secondary disk... which brings us back to square one: you need to fix the security hole... once you have fixed that hole and have checked everything else (and then done a fresh install using the new information) then make a bare metal rescue backup (using partimage, for example) of the system in that state BEFORE IT'S EXPOSED ONTO THE NETWORK... this way if you get owned again you can unplug the network, do the bare metal rescue, and fix whatever went wrong before putting the machine on the network once again...

in other words, the rescue disk is just buying you time, by letting you start-off from a pre-installed/configured system, but you'll still have to fix the security hole before going back online...

if you find yourself actually using this kinda backup on a regular basis, then you need to take a serious look at your general security strategy, because something is terribly wrong... maybe you are using a distro that isn't providing any more security updates... maybe you have misconfigured one of your daemons... maybe you've had a rootkit installed all this time... it could be any number of things...

but one thing is for sure: relying on bare metal rescues for security is a VERY BAD idea...

Last edited by win32sux; 04-22-2005 at 06:33 PM.
 
Old 04-23-2005, 03:56 PM   #6
rockwell_001
LQ Newbie
 
Registered: Jun 2004
Posts: 23

Original Poster
Rep: Reputation: 15
thanks for ur replies guys, i will not work on it and let you know........
 
Old 04-29-2005, 10:47 AM   #7
rockwell_001
LQ Newbie
 
Registered: Jun 2004
Posts: 23

Original Poster
Rep: Reputation: 15
sorry guys i meant to say i will work on it and let u know .......
 
Old 04-29-2005, 06:08 PM   #8
trickykid
LQ Guru
 
Registered: Jan 2001
Posts: 24,149

Rep: Reputation: 269Reputation: 269Reputation: 269
Install or configure some kind of intrusion detection also on your network/systems, something like tripwire. But yes, just simply restoring the system is not solving the problem in whole. Stop the person from attacking/cracking your system is the first step you should take and then your next step is to prevent it from happening again. Then worry about restoring your system if it ever happens again, but hopefully the first two steps get rid of that problem altogether.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
DISCUSSION: Using Linux to backup and recover Windows and Linux systems shshjun LinuxAnswers Discussion 3 12-05-2009 09:42 PM
How do YOU backup Linux? paulinimus Linux - Software 11 08-26-2004 05:34 AM
Linux backup usb1 Linux - Software 13 11-09-2003 07:48 PM
Linux backup juno Linux - General 2 11-04-2002 10:29 PM
How to backup my linux CobraMagic Linux - General 4 09-13-2002 11:08 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 04:22 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration