LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-10-2004, 08:17 PM   #1
OlRoy
Member
 
Registered: Dec 2002
Posts: 306

Rep: Reputation: 86
Making a audit disk


I'm thinking of making a disk using trusted binaries and a shell script to audit a linux box to see if it has been compromised. Heres what i have so far. Are there any problems with this, or other things i should look for?

Collect MAC times of files associated with integrity check and other affected files
date
uname -a
Run bash file integrity script
Check for rootkits especially LKM using ./chkrootkit -p /cdrom/bin and kstat -s -P -M
find S/GUIDs and compare with previous list
find suspicious directories/files ".*", " *", "* *" and compare with previous list
find new file in /dev and /bin by using diff
find accounts with no password, or new root accounts. Maybe any new accounts
find un-owned files, world-writable files and directories
 
Old 04-10-2004, 09:04 PM   #2
jailbait
LQ Guru
 
Registered: Feb 2003
Location: Virginia, USA
Distribution: Debian 12
Posts: 8,337

Rep: Reputation: 548Reputation: 548Reputation: 548Reputation: 548Reputation: 548Reputation: 548
You could check to see if any new ports have been opened.

___________________________________
Be prepared. Create a LifeBoat CD.
http://users.rcn.com/srstites/LifeBo...home.page.html

Steve Stites
 
Old 04-11-2004, 01:42 PM   #3
OlRoy
Member
 
Registered: Dec 2002
Posts: 306

Original Poster
Rep: Reputation: 86
Yeah thats definately a important thing to check but i figured i'd leave that off the disk and scan the host remotely with nmap since the results would be more trustworthy.
 
Old 04-11-2004, 05:40 PM   #4
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
have you checked-out FIRE???

http://fire.dmzs.com/
 
Old 04-11-2004, 07:31 PM   #5
OlRoy
Member
 
Registered: Dec 2002
Posts: 306

Original Poster
Rep: Reputation: 86
Yup but i want a somewhat automated disk to detect a intrusion, FIRE is used more to investigate a intrusion.
 
Old 04-12-2004, 01:07 PM   #6
OlRoy
Member
 
Registered: Dec 2002
Posts: 306

Original Poster
Rep: Reputation: 86
Heres a few other tools that i will probably add to it

ftimes http://ftimes.sourceforge.net/FTimes/index.shtml
fcheck and dirscan http://www.geocities.com/fcheck2000/download.html
 
Old 04-12-2004, 04:22 PM   #7
thetwin
Member
 
Registered: Feb 2003
Distribution: Linux RedHat 7.2
Posts: 47

Rep: Reputation: 15
interesting stuff................Will you be posting the way the disk was made..for exampe all the steps needed and in what order to make this disk

Cheers
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Making Disk RAID ilnli Linux - General 3 07-18-2005 09:52 AM
Making a boot disk Pyro*1 DamnSmallLinux 7 01-04-2004 07:42 PM
Making a boot disk linuxboy69 Linux - General 1 11-03-2003 02:03 PM
Hard Disk question - Making a big hard disk MrAnonym Linux - General 2 09-15-2003 06:08 PM
making a setup disk KnightAbel Linux - Newbie 5 10-05-2002 01:51 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:33 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration