LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-15-2004, 01:41 AM   #1
Kerr
Member
 
Registered: Mar 2004
Distribution: Mandrake 10
Posts: 30

Rep: Reputation: 15
security in Mandrake 10 over LAN


Hi,

I use Mandrake 10 on my machine and it is connected to a 10 mbps LAN connection. Recently somebody hacked my comp and did nasty things on my comp.
Can somebody please suggest me some wat through which I can make my comp secure from such attacks!
 
Old 06-15-2004, 03:46 AM   #2
iainr
Member
 
Registered: Nov 2002
Location: England
Distribution: Ubuntu 9.04
Posts: 631

Rep: Reputation: 30
Hi Kerr,

From the information you've given (not very much) the best place to start is unSpawn's excellent collection of security links
http://www.linuxquestions.org/questi...threadid=45261

If you can give more information about your specific attack, people should be able to answer any questions you have, but the links page is the best place to start.
 
Old 06-15-2004, 03:50 AM   #3
jschiwal
LQ Guru
 
Registered: Aug 2001
Location: Fargo, ND
Distribution: SuSE AMD64
Posts: 15,733

Rep: Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682
You will want to read through some howto's on security. One thing you can do is go into the MCC setup and increase your security level. You also want to be able to receive the security notices via your local mailbox (either as yourself or as root). Or use webmin to read these messages. Go into the firewall setup and make sure that to unselect servers you don't want exposed to the network.
In the system->services section, turn off any services you don't use. Make sure you don't use telnet for instance. Do you need an ftp server on your machine, etc.

Make sure to install all of the security updates. The person who did this may have used an exploit that you haven't upgraded against.

The bad news is that you may need to reinstall. System commands may have been replaced with hacked versions. The person may have altered the logs to cover his steps.
After reinstalling, back up the system files like /bin,/sbin/,/usr/sbin,/etc etcetera.

Use the find command to locate all setuid and setguid programs. Are they needed?

Study the logs. Maybe the hacker didn't catch anything.

Learn about the 'snort' program. This program provides stateful monitoring of network connections.

I'm sure I missed plenty.
A lot to learn an do! Sorry! Good luck in the future.
 
Old 06-18-2004, 08:04 AM   #4
Kerr
Member
 
Registered: Mar 2004
Distribution: Mandrake 10
Posts: 30

Original Poster
Rep: Reputation: 15
Hi,

it seems that my last posted message did not appear on the board.

Anyway, I am thankful to you people for replying, as far as the attack on my comp is concerned, it was most probably a Buffer overflow attack( as analyzed by somebody!),. Although I am right now learning how to make my comp robust for such things. Putting up a firewall may be a good option, but then I have to run a DC client on my machine, which eventually stopped working after the firewall was turned On.
The person who cracked his/her way to my comp, deleted the kernel and the log files, so I couldn't trace him back .

Thank you Iainr, for the link, I probably need to spend more time to learn all the Linux security stuff.
 
Old 06-18-2004, 05:44 PM   #5
Kerr
Member
 
Registered: Mar 2004
Distribution: Mandrake 10
Posts: 30

Original Poster
Rep: Reputation: 15
Ok, so does anybody know, how should I set up my firewall and security setting, so that my dc client works fine, and the danger of cracking and stuff is also avoided ? I could not find any related stuff from the links I followed :-(

I am confused !
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Whats a magic packet (wake on lan) (in terms of routability, and security) qwijibow Linux - Hardware 1 01-28-2005 06:52 PM
Internal LAN security.. mixed platforms! rohan208 Linux - Networking 3 09-22-2004 02:27 PM
LAN security - how many layers of protection? svarreby Linux - Security 3 03-19-2004 06:41 AM
what security Mandrake provides? please help salsaholik Linux - Security 2 05-14-2003 12:14 AM
Security in Mandrake 7.2 gomer1701ems Linux - Security 1 03-29-2001 02:03 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:13 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration