Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here. |
Notices |
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
Are you new to LinuxQuestions.org? Visit the following links:
Site Howto |
Site FAQ |
Sitemap |
Register Now
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
Get a virtual cloud desktop with the Linux distro that you want in less than five minutes with Shells! With over 10 pre-installed distros to choose from, the worry-free installation life is here! Whether you are a digital nomad or just looking for flexibility, Shells can put your Linux machine on the device that you want to use.
Exclusive for LQ members, get up to 45% off per month. Click here for more info.
|
 |
05-05-2006, 09:18 AM
|
#1
|
LQ Newbie
Registered: May 2004
Posts: 14
Rep:
|
a port scan ran from my pc
i noticed that a port scan ran from my pc, what do i need to check for to make sure i fix this security hole?
I reset the user account password they used (mythtv). but not sure if they somehow managed to get my root password. I have a wireless router, with only a few ports opened, for mythtv, remote desktop, etc. I dont broadcast my ssid, and have wep enabled, there does not seem to be any new services running from my linux box. then again, i really have no idea what to look for.
Any help would be greatly appreciated.
Thanks
|
|
|
05-05-2006, 01:40 PM
|
#2
|
Member
Registered: Apr 2006
Location: Pittsburgh
Distribution: Debian Sid AMD64
Posts: 296
Rep:
|
Once a machine has been compromised, I wouldn't trust it no matter how much you can check for. Best to just reinstall it, and reinstall your data from backup.
|
|
|
05-05-2006, 01:49 PM
|
#3
|
Senior Member
Registered: Sep 2005
Location: France
Distribution: approximately NixOS (http://nixos.org)
Posts: 1,900
Rep:
|
What is source of confidence that scan was from that machine, and not just masquaraded?
|
|
|
05-05-2006, 02:08 PM
|
#4
|
LQ Newbie
Registered: May 2004
Posts: 14
Original Poster
Rep:
|
when i look in my history i see several entries that i did not type in that are suspect i.e
./start 80.52
./start 80.53
./start 80.54
./start 62.40
./start 62.41
etc, etc, etc and also an entry of paypal.php, i can also see a website where the app seems to have been downloaded. etc.
|
|
|
05-05-2006, 02:12 PM
|
#5
|
Senior Member
Registered: Sep 2005
Location: France
Distribution: approximately NixOS (http://nixos.org)
Posts: 1,900
Rep:
|
Then I tend to agree with the idea to reinstall.
|
|
|
05-05-2006, 02:14 PM
|
#6
|
LQ Newbie
Registered: May 2004
Posts: 14
Original Poster
Rep:
|
thanks
not the answer i was hoping for, but thats what i get for being lazy! thanks againg for the advice.
|
|
|
All times are GMT -5. The time now is 07:26 PM.
|
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.
|
Latest Threads
LQ News
|
|