LinuxQuestions.org

LinuxQuestions.org (/questions/)
-   Linux - Security (https://www.linuxquestions.org/questions/linux-security-4/)
-   -   So How often does everyone scan their Linux Computers and what do you use? (https://www.linuxquestions.org/questions/linux-security-4/so-how-often-does-everyone-scan-their-linux-computers-and-what-do-you-use-839646/)

meetscott 11-01-2010 01:16 PM

Samhain is free. People should check it out and run it daily at night. There's no reason not to. You'll never even notice it's there unless something happens.

H_TeXMeX_H 11-01-2010 01:39 PM

Quote:

Originally Posted by meetscott (Post 4146016)
Samhain is free. People should check it out and run it daily at night. There's no reason not to. You'll never even notice it's there unless something happens.

There's also no reason to use it, unless you're running a server.

meetscott 11-01-2010 01:41 PM

Quote:

There's also no reason to use it, unless you're running a server.
Malware is only a problem on servers?

But I guess I can accept the argument that it might be a little overkill.

cincindie 11-01-2010 01:43 PM

I rarely if ever perform a regular scan of the whole system. I do monitor the logs and look for unusual activity. Otherwise, e-mails on the server are the only things that get scanned on a regular basis.

mesiol 11-01-2010 01:49 PM

Hi,

rkhunter and chkrootkit on a daily base works okay for me. AV software running on my mailservers, but not locally on my workstation. Never found anything not intented by myself to be there.

nomb 11-01-2010 02:12 PM

Quote:

Originally Posted by meetscott (Post 4146037)
Malware is only a problem on servers?

But I guess I can accept the argument that it might be a little overkill.

I can't. I think you should run a HIDS on all of your boxes.

clifford227 11-01-2010 03:13 PM

Could audio files (mp3, flac, etc) or video files (avi, mpg, mkv, etc) contain exploits or trojans?

My external backup drives contain mostly media files and ofcourse you cant do a reformat or you lose all your stuff.

What is the best practice for protecting external backup drives?

Amdx2_x64 11-01-2010 03:23 PM

Quote:

Could audio files (mp3, flac, etc) or video files (avi, mpg, mkv, etc) contain exploits or trojans?
From my understanding, yes. I also believe jpg's or other image formats can as well. Though I am not sure how this is done or for that matter how likely, even if possible, it would be.

Hangdog42 11-01-2010 04:39 PM

Quote:

Originally Posted by clifford227 (Post 4146109)
Could audio files (mp3, flac, etc) or video files (avi, mpg, mkv, etc) contain exploits or trojans?

My external backup drives contain mostly media files and ofcourse you cant do a reformat or you lose all your stuff.

What is the best practice for protecting external backup drives?

Unless I've missed something, unless your media files are executable (and I have no idea why someone would let data be executable), they can't do damage. Simply opening a media file in its appropriate viewer shouldn't allow any damage.

unSpawn 11-01-2010 06:06 PM

Quote:

Originally Posted by H_TeXMeX_H (Post 4146034)
There's also no reason to use it, unless you're running a server.

Given the fact that some OS installations are not that well-protected out of the box (Ubuntu's Remote Desktop comes to mind, see for instance the reports on Ubuntuforums), some users not knowing or caring for any security and the amount of hosts being compromised through the web stack still, I disagree.

win32sux 11-01-2010 06:13 PM

Quote:

Originally Posted by clifford227 (Post 4146109)
Could audio files (mp3, flac, etc) or video files (avi, mpg, mkv, etc) contain exploits or trojans?

They most certainly can. In fact, as pointed out by Amdx2_x64, even image files can contain exploits.

Image example: CVE-2010-1205; Audio example: CVE-2007-6279; Video example: CVE-2009-3389.

unSpawn 11-01-2010 06:17 PM

Quote:

Originally Posted by Amdx2_x64 (Post 4135283)
I was just curious how many times the average Linux desktop user at these forums check their computer for virus', root kits, etc. (..) So How often does everyone scan their Linux Computers and what do you use?

Next to whatever basic hardening / logging entails I use GNU/Tiger or LSAT, Auditd, Samhain (daemon: active) or Aide (cronjob: passive), Snort, a slightly modified Chkrootkit, Rootkit Hunter with add-ons and some home-brewn scripts. If I run AV SW it'll mostly be to help determine stuff sent to me or found elsewhere.

unSpawn 11-01-2010 06:19 PM

Quote:

Originally Posted by win32sux (Post 4146235)
image files can contain exploits.

...and next to that PHP scripts are often uploaded with image type extensions to bypass crude filters.

meetscott 11-01-2010 06:22 PM

It's easy to get way off base here. Install as much security as you can and then back off based on usability and cost limitations. Sometimes extra security does not return anything given what is being protected.

Sometimes "Fort Knox" style is the appropriate path if what you are protecting is worth the investment. I like to see costs (processing, I/O, admin time), barriers (knowledge, time, training, etc.) and investment (research, setup, etc.) be so low that people can't help but be secure and make good choices.

I think we are moving closer and closer to that with Linux and options we have today. This forum also contributes to that greater good.

unSpawn 11-01-2010 06:34 PM

Define "extra security"?


All times are GMT -5. The time now is 06:00 PM.