LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-16-2010, 12:49 PM   #16
Hangdog42
LQ Veteran
 
Registered: Feb 2003
Location: Maryland
Distribution: Slackware
Posts: 7,803
Blog Entries: 1

Rep: Reputation: 422Reputation: 422Reputation: 422Reputation: 422Reputation: 422

Quote:
Originally Posted by metallica1973 View Post
Many thanks for all the responses. How is my firewall looking?
To be honest, I'm not sure what I think about your firewall. It is obvious that you've got a pretty complex setup, and without knowing more about what services the machine is supposed to be offering and what you're trying to defend against, I'm not sure I could offer much in the way of practical analysis.

Given the amount in your FORWARD chain, I'm guessing this is acting as some sort of a router or gateway between domains. If this is true, and if we find evidence of a compromise, that could raise the troubling issue of whether or not any of the other systems sharing this network have been infected/attacked.

I'm also not sure I understand what is going on in the OUTPUT chain. It looks like you eventually accept everything heading outbound, so I'm kind of wondering why you don't just set the OUTPUT default to ACCEPT. Unless I'm missing something (always a possibility), no packets ever make it from OUTPUT to the LDROP table.

One thing I will say is that in terms of this potential compromise, I'm not sure the firewall is something to be concerned about. It is clear you have it doing a fair bit of logging, and they may be useful once we have a better picture going on. What this firewall also may do is make it a bit more of an imperative to look at existing services and see if they have been compromised. It might be a bit difficult with this firewall to set up a new service like an IRC server and have it be accessible without changing some rules.
 
Click here to see the post LQ members have rated as the most helpful post in this thread.
Old 10-11-2010, 06:50 AM   #17
metallica1973
Senior Member
 
Registered: Feb 2003
Location: Washington D.C
Posts: 2,190

Original Poster
Rep: Reputation: 60
many thanks for your advice, I will take a peak and the firewall and go through it with a fine comb.
 
Old 10-11-2010, 12:03 PM   #18
Hangdog42
LQ Veteran
 
Registered: Feb 2003
Location: Maryland
Distribution: Slackware
Posts: 7,803
Blog Entries: 1

Rep: Reputation: 422Reputation: 422Reputation: 422Reputation: 422Reputation: 422
Just out of curiosity, have you done any digging into how the root password got changed? The firewall is a secondary priority if you've been cracked.
 
Old 10-11-2010, 07:11 PM   #19
metallica1973
Senior Member
 
Registered: Feb 2003
Location: Washington D.C
Posts: 2,190

Original Poster
Rep: Reputation: 60
after thinking about it very careful, I have reason to believe that it happened after several updates to were done to the server. It was immediately after the updates where complete is when I couldn't login. I checked everything possible on the system and cant find anything abnormal.I ran chrootkit and others like it without finding anything. I will reformat it here shortly to be sure but. I really think it was the updates that caused the issues.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
root password changed lemon09 Linux - Newbie 8 08-18-2009 04:50 AM
My root password has changed?!!! defa0009 Linux - Security 35 05-18-2005 04:49 PM
system changed my root-password supersucker Linux - Software 2 01-16-2005 01:12 PM
Help Root password changed!!! UmneyDurak Fedora 4 09-28-2004 01:47 PM
someone changed my root password. what do i do? budds Linux - Security 4 09-12-2004 12:09 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:14 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration