LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Closed Thread
  Search this Thread
Old 09-30-2003, 02:25 PM   #1
khermans
Member
 
Registered: Sep 2001
Distribution: Ubuntu, Debian, Gentoo
Posts: 162

Rep: Reputation: 30
Blocking local TTY terminal text floods ???


I'm having a problem. Some people think its funny to flood my screen with text while I'm on a linux box at school, but I'm getting sick of it to tell you the truth. I successfully blocked the WRITE command using "mesg n", which shuts off the ability to send/receive messages using the WRITE command. But now flooding is still possible with TALK, WALL, and ECHO (/dev/ttyxx). Can anyone help me derail these local text-based DoS attacks??? Thanks in advance...

Kris Hermansen
 
Old 09-30-2003, 10:15 PM   #2
m0rl0ck
Member
 
Registered: Nov 2002
Distribution: A totally 133t distro :)
Posts: 358

Rep: Reputation: 31
Who is doing this? Just did a couple of tests and it seems that only a superuser can write to a tty if mesg is set to n. Is this person whos persecuting you running as root?
 
Old 09-30-2003, 10:43 PM   #3
khermans
Member
 
Registered: Sep 2001
Distribution: Ubuntu, Debian, Gentoo
Posts: 162

Original Poster
Rep: Reputation: 30
I have no idea how he is doing it...but I can tell you that I'm pretty sure he's not root. Is there any way to trace the attack? I can gain root on the box using the kmod/ptrace exploit and see everything that is happening. I know that he has created a service to DoS me everytime I logon to the system. It checks for my user name, then floods me. I can't stop it with CTRL-X/CTRL-Z either. Just keeps on coming. ;-( Even if he did have root, if I can gain root too, can I stop it in any way OTHER than killing the running process? Like some sort of prevention technique? Like, refusing to accept any output to TTY from anyone other than ME??? I am kinda frustrated. I know what I can do...I will exploit to root with ptrace and grab the file in his local directory (that does the DoS) and see what's going on. If I can;t understand it, I'll show it here. Let me know if you have any other suggestions...

Kris Hermansen
 
Old 09-30-2003, 10:59 PM   #4
m0rl0ck
Member
 
Registered: Nov 2002
Distribution: A totally 133t distro :)
Posts: 358

Rep: Reputation: 31
If you can get root on the box the person whos doing this probably can too.
The first thing to try is just report the attacks to your sysadmin, if that doesnt work (did you already try it?) run ps aux -ww as another user and as yourself save the results to textfiles and diff the textfiles. That should give you a place to start looking for the script or whatever thats doing it.
First try working within the existing admin structure, no need to expose yourself to official reprisals except as a last resort.
 
Old 09-30-2003, 11:10 PM   #5
khermans
Member
 
Registered: Sep 2001
Distribution: Ubuntu, Debian, Gentoo
Posts: 162

Original Poster
Rep: Reputation: 30
We are doing this for fun to one up each other. The admins are dumb anyway. They always have nice default passwords on everything and never patch their machines. And I'm just trying to figure out how he is doing this with non-root priviledges. I will post his script here after I intercept it. Until then...hang tight and thanks for the info!!

Kris Hermansen
 
Old 09-30-2003, 11:25 PM   #6
m0rl0ck
Member
 
Registered: Nov 2002
Distribution: A totally 133t distro :)
Posts: 358

Rep: Reputation: 31
"We are doing this for fun to one up each other. "

Well in that case, if your both abusing the system just for the fun of it, you deserve what your getting, dont be suprised if your "stupid" admins catch you both and revoke your login privs. Thats what I would do anyway. In addition, you shouldnt be on this forum asking for help to circumvent your schools computer security measures or the sysadmins authority. At first I thought you were an innocent victim of a prank, I see now that your as culpable as the person dosing you, you dont deserve help, you deserve at the very least, a spanking.
By the way, is that your real name at the bottom of your posts?
 
Old 10-01-2003, 03:30 AM   #7
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
//moderator.note: khermans, LQ is not the board to ask for exploits or ask for help with exploiting vulnerable conditions in applications. Please visit another board with these type of questions. Thread closed.
If you, after having read and understood the rules you agreed to adhere to when you signed up, want to dispute my moderation actions, you're welcome to take it up with me by mail.
 
  


Closed Thread



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
direct ssh commands to local tty? mikeybsae Linux - Software 1 08-18-2004 03:42 PM
tty usb terminal? DarkstarNL Linux - Hardware 0 04-21-2004 09:34 AM
Blocking TTY terminal text floods ??? khermans Linux - General 1 10-01-2003 07:12 AM
Preventing local users from "text flooding" a terminal (DoS attack)... khermans Linux - Security 2 09-24-2003 07:56 AM
Need help! Prism2 wireless card stops working, floods terminal with errors Electrode Linux - Wireless Networking 6 02-05-2003 10:37 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:26 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration