LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-02-2016, 07:40 PM   #1
k.um
LQ Newbie
 
Registered: Jul 2009
Posts: 12

Rep: Reputation: 0
Preventing intrusion into PC.


My system is Slackware14.1 and KDE 4.10.
Now I'm in trouble, as PC is intruded when it does't connect to Network and internet.
but regrettably, I can't hide only any username and passward.

What is supposed, is through
1. wireless network.
Its demon isn't active.
2. power line communication.
I did't know entirely the way to prevent this.
Would you teach me these prevention?
In addition, I'd like to know how to stop port 6000 at KDE desktop.

Thanks for your helps!

Last edited by k.um; 01-02-2016 at 07:43 PM.
 
Old 01-02-2016, 08:27 PM   #2
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,321
Blog Entries: 28

Rep: Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141
Do you have powerline networking appliances installed in your location? It can't be done without special equipment.

What evidence do you have of intrusion?

Also, if it's not already installed, install fail2ban.

If you think this intrusion is coming from outside, you should be able to close down port 6000 in your router. Otherwise, you can do it in iptables. If you do not have a good frontend for iptables, I can recommend ufw; there's a Slackbuild for a KDE GUI frontend for ufw.

Frankly, if you think someone who has physical access to the machine is accessing it and you cannot hide your user name and password (is this maybe a school or company machine, rather than your personal machine?), there may be little you can do in software.

Last edited by frankbell; 01-02-2016 at 08:30 PM.
 
1 members found this post helpful.
Old 01-06-2016, 07:46 PM   #3
k.um
LQ Newbie
 
Registered: Jul 2009
Posts: 12

Original Poster
Rep: Reputation: 0
Thanks your teaching!

I have no powerline network appliiances.

And no evidences, but in standalone, cups printing have gone to abnormal behavior, and when I use scim-anthy in Japanese input, the candidate of transformation is occasionally gone back to the default though this must be the newest. This two wrong behavior are problems.

When anyone boots my PC or shutdowns, the date-time is logged the file, therefore anyone didn't operate physically, but someone may go into my room.

Now, I installed fail2ban and kcm-ufw. Also before I use iptables firewall and so make the drop rule of port 6000, but nmap shows that 6000 is opened.

Thanks good advices.

Last edited by k.um; 01-06-2016 at 07:48 PM.
 
Old 01-06-2016, 08:03 PM   #4
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,321
Blog Entries: 28

Rep: Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141
Thanks for the update.
 
Old 01-16-2016, 01:20 PM   #5
Drakevr
Member
 
Registered: Jan 2013
Location: Greece
Distribution: Slackware64, openBSD
Posts: 38

Rep: Reputation: 7
6000 is used locally by default, it's the port Xorg uses and it doesn't allow network connections unless you explicitly configure it to do so.
 
Old 01-17-2016, 05:43 PM   #6
k.um
LQ Newbie
 
Registered: Jul 2009
Posts: 12

Original Poster
Rep: Reputation: 0
Thanks for the detail information.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Possible server intrusion ShellPwn Linux - Security 37 11-30-2009 10:01 AM
Intrusion attack bogwato Linux - Security 1 07-15-2009 01:20 PM
Possible Intrusion Attempt mcupples Linux - Security 6 04-24-2007 09:31 AM
intrusion? tincat2 Linux - Security 2 01-01-2005 01:56 AM
Intrusion Detection? matador Linux - Security 5 09-03-2003 04:44 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:53 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration