LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-04-2003, 07:11 AM   #1
Jusitn S
LQ Newbie
 
Registered: Nov 2003
Distribution: fedora
Posts: 7

Rep: Reputation: 0
opinions if this server has been rooted


First, thanks for taking the time to read this post.

I would like your opinions on why I cannot log into this machine as root.

I recently set up this linux box (Redhat 9) for FTP usage (VSFTPD). On the router, I have opened ports 20,21, and 22. Running nmap on the linux box shows that ftp, ssh, http, snet-sensor-mgmt (Webmin) and netbios-ssn (Samba)are open and can be access internally.

This machine has only been up for an aggregate of 7 hours. As of yesterday I cannot log into this machine with the root account as it complains that the password is incorrect. I have written all of the passwords, configurations, etc in a notebook during the installation so I know it isn't a question that I forgot the password.

Do I justification to suspect that this machine has been compromised albiet very quickly, or am I jumping the gun here?
 
Old 11-04-2003, 07:17 AM   #2
glj
Member
 
Registered: Jul 2001
Location: London
Distribution: RH 9
Posts: 151

Rep: Reputation: 30
I think your jumpin' the gun.
It isn't a good idea to log into a machine remotley using the root account, so this is turned off by default. This is true of SSH and ftp probably.
Log in using a 'normal' account then use 'su' to gain root privileges.

glj
 
Old 11-04-2003, 10:00 AM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
I would like your opinions on why I cannot log into this machine as root.
Determining if a compromise happened is no matter of opinions: you should be looking for facts and deal with those. besides that, a box (suspected) being compromised is different from not being able to log in as root. If you have "evidence" a box is rooted take it off the 'net and then audit it, if you suspect a box to be compromised you should audit the box (auth, logs, integrity, processes), and if you can't log in as root you should review your configuration. That's the way to deal with suspicions about abox integrity.
Like Glj said you should use sudo and not log in as root directly. If you argue for making exceptions "just cuz it's on the LAN" you'll be making exceptions all the time. Bad habit.
BTW you didn't specify logging in as root how: local, SSH etc etc.


This machine has only been up for an aggregate of 7 hours.
Time is no mitigating argument. What state was it in?
Where there more/other/to-be-upgraded services running?
Was access denied by it's firewall and the router all of the time?
What hardening/configuration modifications did you make?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Game Server Opinions Hootah Linux - General 0 09-19-2004 07:23 PM
Which distro for ftp server(need some opinions) poweroff Linux - General 4 03-22-2004 05:47 AM
Opinions on server build... BrianPM Linux - Newbie 8 06-19-2003 03:55 PM
many workstations, one music server - need opinions d33pdream Linux - General 4 03-05-2003 10:51 PM
Opinions please - Which distro for office server ? Justinw Linux - Distributions 9 05-24-2001 08:22 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:25 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration