LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-27-2004, 05:33 PM   #1
Shr00mBoXx
Member
 
Registered: Dec 2003
Distribution: Slackware 9.1
Posts: 63

Rep: Reputation: 15
Catching a Hacker...


ok... well I am not the biggest into security... but I need some help... an ex friend of mine has been cracking into my computer and doing little things
i.e opening up giFTcurs and downloading gay porn, changing hotmail settings so all text is in jap, requesting passwords of mine...

well last night I come home from work... open up XMMS and click play... NOTHING works... I am like wtf... so I restart my computer and it cant find anything to boot from... so I pop my slack disk in... try to install lilo but oh wait nm... the disks are corrupt... cfdisk makes me basically format the disks... well anyway, I am almost positive this was him since it was 2 hard drives... and the odds that BOTH drives died on me the same night... but anyway... I called his ISP along with mine and they said the best thing to do is get logs... so I need a way to get SSH logs... and if it is possible logs of commands that are run... can anyone help me
 
Old 06-27-2004, 06:12 PM   #2
Pcghost
Senior Member
 
Registered: Feb 2003
Location: The Arctic
Distribution: Fedora, Debian, OpenSuSE and Android
Posts: 1,820

Rep: Reputation: 46
Once you get your machine up and you read up on securing services, setup Snort and Tripwire. The first is a packet sniffer/intrusion detection system, and the other is a file system IDS. Make sure you output logging somewhere else, like a different machine if possible. Then the next time the little script kiddie gets a wild hair and 0wn3s your machine, you will have a record of what he did and where (ip) he did it from.
 
Old 06-27-2004, 06:41 PM   #3
fotoguy
Senior Member
 
Registered: Mar 2003
Location: Brisbane Queensland Australia
Distribution: Custom Debian Live ISO's
Posts: 1,291

Rep: Reputation: 62
I would also consider running a dedicated firewall like Smoothwall or Ipcop. Both of these distros already have snort included and setup. They will gladly log everything that hits the firewall, it will stop him from getting in as well. They block all incoming request that have not originated from inside the network by default.
 
Old 06-27-2004, 11:39 PM   #4
Shr00mBoXx
Member
 
Registered: Dec 2003
Distribution: Slackware 9.1
Posts: 63

Original Poster
Rep: Reputation: 15
Well just an FYI... he isn't a "script kiddie" he is more of a pathetic excuse for a human... who knows my passwords... I have SSH up and running for my personal use... he iwll just SSH my computer and login that way... so I dont feel packet monitoring will be useful but... btw I am installing Gentoo now... so if anything is different between gentoo and slack just tell me, and I have a firewall up with an internal firewall
 
Old 06-27-2004, 11:52 PM   #5
Joey.Dale
Member
 
Registered: Jun 2003
Location: Tampa, Fl
Distribution: Gentoo, Slackware
Posts: 828

Rep: Reputation: 39
change the f***'n password

-Joey
 
Old 06-28-2004, 01:02 AM   #6
orange400
Member
 
Registered: Mar 2003
Location: Bellevue, WA
Distribution: Arch w/ XFCE
Posts: 834

Rep: Reputation: 30
haha ... werd. Did you know that MD5s take 20 trillion years to crack with our current technology?

BTW - Smoothwall rules ... I've had someone busting into my router every other day. Now, the activity light on the cable modem blinks, but on the router, it doesn't And it's snorted all sorts of things, like attempted virus implants, attempted information leaks, attempted shell hacks, etc ...
 
Old 06-28-2004, 07:56 AM   #7
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
As far as recovering data (including logs) from the hd, take a look at the LQ security references thread that unSpawn's put together. There is an entire section on undeleting and recovering partitions here.
 
Old 06-28-2004, 03:04 PM   #8
gensis
LQ Newbie
 
Registered: Jun 2004
Distribution: Slackware, Suse, Red Hat, Fedora
Posts: 28

Rep: Reputation: 15
i recommand u carry a big bat... next time u see your friend give him hell ^^

All that aside, dont give him your ip, if your ip is static call your isp and change it.
Using snort, tripwire, smoothfirewall, or some sort of NAT device to stop that bugger, installing personal firewalls help too. Since he is your "friend" call him up on the phone and talk serious about this. And dont give into soical engineering either ^^
 
Old 06-28-2004, 06:06 PM   #9
J.W.
LQ Veteran
 
Registered: Mar 2003
Location: Boise, ID
Distribution: Mint
Posts: 6,642

Rep: Reputation: 87
I would second joey.dale's recommendation -- in addition to hardening your system, I would immediately change your passwords to something wildly different than whatever you've been using. Most people have a tendency to use the same password for multiple systems, or for their passwords to be variations on the same general theme. If this guy knows your password(s) already, and he knows you pretty well, then chances are reasonably high that even if you change your password to something else, the degree of difference between the old and the new may not be sufficient. Thus, I'd advise you to change it to something completely unlike anything you've used before, and follow the standard rules: it should include letters and numbers, mixed case, the longer the better, etc. Good luck cleaning things up -- J.W.
 
Old 06-29-2004, 12:26 AM   #10
Shr00mBoXx
Member
 
Registered: Dec 2003
Distribution: Slackware 9.1
Posts: 63

Original Poster
Rep: Reputation: 15
Well when your password consists of random letters and numbers up and lower case... it is sorta hard to change them from what you normaly use... along with that... it is hard to change my IP because he has ways of figuring it out... i.e I host my own website and the fact that I visit webpages that logs IPs which he has access to, and talk to people who he has access to... but besides that... changing my IP address and password will not stop him from attacking... I dont know if it is still possible but I have already started installing gentoo and xp on the hard drive again... I dont know if the place where the logs were has been written over or not... when I get gentoo installed (yes I am slow at it because I suck at reading manuals) but when I get gentoo up and running I will enable all of that... thank you all for your help
 
Old 06-29-2004, 01:44 AM   #11
J.W.
LQ Veteran
 
Registered: Mar 2003
Location: Boise, ID
Distribution: Mint
Posts: 6,642

Rep: Reputation: 87
Quote:
Originally posted by Shr00mBoXx
Well when your password consists of random letters and numbers up and lower case... it is sorta hard to change them from what you normaly use... along with that... it is hard to change my IP because he has ways of figuring it out...
Well, No. Changing your PW is easy, and should be done immediately. Obviously, if you have a website it would be a piece of cake to determine its IP address, and Yes, it's true that you can't prevent a malicious person from trying to attack your site, but you definitely can protect your site by changing the password to a new value. -- J.W.
 
Old 06-29-2004, 02:19 AM   #12
ppuru
Senior Member
 
Registered: Mar 2003
Location: Beautiful BC
Distribution: RedHat & clones, Slackware, SuSE, OpenBSD
Posts: 1,791

Rep: Reputation: 50
Here are some sites that can help you generate a new password... that are perhaps a bit difficult to remember

http://www.winguides.com/security/password.php
http://www.multicians.org/thvv/gpw.html

You can find plenty if you google for them
 
Old 06-29-2004, 03:45 PM   #13
v00d00101
Member
 
Registered: Jun 2003
Location: UK
Distribution: Devuan Beowulf
Posts: 514
Blog Entries: 1

Rep: Reputation: 37
Quote:
Originally posted by Shr00mBoXx
it is hard to change my IP because he has ways of figuring it out... i.e I host my own website and the fact that I visit webpages that logs IPs which he has access to, and talk to people who he has access to... but besides that... changing my IP address and password will not stop him from attacking...
To get rid of him knowing your ip address from where u browse, maybe consider using a web proxy to make him think your ip is something other than it is.

If you know for sure he has access, and although it may be a bit unethical, why not think about leaving him a surprise or maybe doing some of the same back to him.
 
Old 06-30-2004, 12:45 PM   #14
320mb
Senior Member
 
Registered: Nov 2002
Location: pikes peak
Distribution: Slackware, LFS
Posts: 2,577

Rep: Reputation: 48
you can also set your system to "REFUSE" connection from "HIS" ISP also.
It"s kind of crappy to refuse a whole host of people like that but.........
you can also set it up to "refuse" concection from his "IP Address" also..........
 
Old 06-30-2004, 09:59 PM   #15
ppuru
Senior Member
 
Registered: Mar 2003
Location: Beautiful BC
Distribution: RedHat & clones, Slackware, SuSE, OpenBSD
Posts: 1,791

Rep: Reputation: 50
Alternative to 320MB's post, you can allow ssh connections only to the IP of the external machine that you connect from.

you can put this entry in /etc/hosts.allow

e.g.

sshd: <your external system's IP>
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
catching signals alaios Programming 3 11-16-2007 05:05 AM
catching a keypress on X MD3 Programming 0 02-14-2005 02:07 PM
Catching first letter. TheRealDeal Linux - General 1 03-28-2004 08:50 PM
Catching a signal? kalleanka Programming 6 02-12-2004 09:44 AM
Question : catching cores Saeven Linux - General 2 06-13-2002 04:29 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:52 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration