LinuxQuestions.org
Help answer threads with 0 replies.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-25-2006, 09:20 PM   #1
mazinoz
Member
 
Registered: Mar 2003
Location: Mansfield Queensland Australia
Distribution: Linux Mint - Tara
Posts: 497

Rep: Reputation: 35
Run restore on boot & LKM rootkits


This may be a question best answered by a moderator, but here goes.

Is it possible when rebooting to run a system 'restore' from the harddrive of a workstation using dar that would undo what has been done by an LKM rootkit? Where exactly in the boot sequence should this happen?

The application for this is for publicly accessible,internet connected PC's such as libraries etc.

Alternatively would it be better to simply reload files from the file server when the PC boots?


Cheers

MazinOz
 
Old 07-26-2006, 01:24 AM   #2
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
If you're considering reloading files from a remote server anyway, another possibility might be simply running from a GNU/Linux live cd, eh? A read-only OS; every admin's dream.
 
Old 07-26-2006, 01:38 AM   #3
Matir
LQ Guru
 
Registered: Nov 2004
Location: San Jose, CA
Distribution: Debian, Arch
Posts: 8,507

Rep: Reputation: 128Reputation: 128
Under windows, there's a tool called Deep Freeze that does this kind of stuff.

I would suggest you look into building a copy-on-write filesystem with the 'writable' portion being a tmpfs (in-ram only). Therefore, on reboot, it reverts to the disk system without any changes made by the previous user.
 
Old 07-26-2006, 06:45 PM   #4
mazinoz
Member
 
Registered: Mar 2003
Location: Mansfield Queensland Australia
Distribution: Linux Mint - Tara
Posts: 497

Original Poster
Rep: Reputation: 35
Cool Run restore on boot & LKM rootkits

Dear anomie and Matir

Thank you for your replies. I was aware of Deep Freeze but my impression of it was that it was tied very much to a Windows operating system. If you have it working successfully for linux please let me know.

A fileserver serving from a CD or DVD is also a good option as well as a ramdrive. The PC's are for a charity and have 256mb RAM with only 2 slots and are picky about what RAM works (Dells), Kingston RAM doesn't always work, though it is recommended. If I used Debian Sarge or Fedora Core 5, would performance levels be acceptable if serving from a 2.8G processor with 750mb RAM? Also I have mainly used SuSE but recently tried Fedora and Debian Sarge, both of which are heaps faster than SuSE out of the box for some reason. Though I have done a major overhaul of a number of things in SuSE I have decided to discontinue using it as it STILL has slower performance than Fedora or Sarge, and there is even a project to hack it to make its speed acceptable.

I'm self-taught and still learning heaps, but what is a copy-on-write file system? Also if I have a prototype setup, how do I make a bootable iso image? mkisofs? An outline of steps involved, or some links would be appreciated.

Cheers

MazinOz
 
Old 07-26-2006, 07:01 PM   #5
Matir
LQ Guru
 
Registered: Nov 2004
Location: San Jose, CA
Distribution: Debian, Arch
Posts: 8,507

Rep: Reputation: 128Reputation: 128
Deepfreeze is indeed for Windows. I was merely comparing my suggestion to the functionality offered by Deepfreeze.
 
Old 07-26-2006, 07:16 PM   #6
mazinoz
Member
 
Registered: Mar 2003
Location: Mansfield Queensland Australia
Distribution: Linux Mint - Tara
Posts: 497

Original Poster
Rep: Reputation: 35
Dear Matir

What I think I want is something like a Linux version of this utility, but don't know how to go about achieving this. What do you mean exactly when you say a copy-on-write filesystem?

Thank you

MazinOz
 
Old 07-26-2006, 07:24 PM   #7
Matir
LQ Guru
 
Registered: Nov 2004
Location: San Jose, CA
Distribution: Debian, Arch
Posts: 8,507

Rep: Reputation: 128Reputation: 128
Take a look at unionfs and this Linux Journal article.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Neutering Rootkits with a File Restore penguinlnx Linux - Security 6 04-01-2005 01:49 AM
webalizer & Error: Unable to restore run data (1) mikeshn Linux - Software 0 01-11-2005 11:39 AM
aslactl restore doesnt run at boot true_atlantis Slackware 6 05-19-2004 09:52 PM
The Daemonic Horde is on the run! (how do I get my snd & net to start up upon boot?) versaulis Linux - Software 3 02-25-2004 05:07 PM
LILO & W2K boot restore anymouse Linux - Newbie 0 01-31-2003 03:45 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:38 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration