LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-24-2004, 11:41 AM   #1
KooPA
Member
 
Registered: Apr 2004
Location: Phili
Distribution: SuSE v9.1 Personal, Slackware (TV Server)
Posts: 53

Rep: Reputation: 15
Updates/Flaw


After installing Mandrake, Mozilla Firefox and Gaim I was just browsing the web (this site) and all of a sudden my computer went nuts. The mouse seemed like it was just constantly left clicking, yet I couldn't open anything (to see what the hell was going on). So I rebooted thinking it was just some sort of weird bug, now I can't su as root (keeps saying bad password yet I know its correct). I thought it asisnine to be hacked, but I check my router and had the firewall down...is it possible that they used to bug to get into me and change the password to my box? are there any updates and where/had whould I get them?
 
Old 04-24-2004, 02:38 PM   #2
KooPA
Member
 
Registered: Apr 2004
Location: Phili
Distribution: SuSE v9.1 Personal, Slackware (TV Server)
Posts: 53

Original Poster
Rep: Reputation: 15
O yea I forgot.
Now I can't run things like K-Menu, it flashes up that its loading then goes right away...Any ideas?
 
Old 04-26-2004, 11:03 AM   #3
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Technically it is possible, but it's hard to say for sure without knowing any facts. Can you log in directly as root? If so, check out your system logs to see what kind of errors you are getting.
 
Old 04-26-2004, 07:10 PM   #4
KooPA
Member
 
Registered: Apr 2004
Location: Phili
Distribution: SuSE v9.1 Personal, Slackware (TV Server)
Posts: 53

Original Poster
Rep: Reputation: 15
no I get the same error when logging in as root, bad pw
 
Old 04-26-2004, 11:28 PM   #5
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
This Mandrake-specific howto should help you reset the root password:

http://www.mandrake.tips.4.free.fr/h...ml#resetrootpw

After that, go through the system logs and look for errors, you should treat this as a potential compromise until you can effectively rule it out. Take a look at the security references thread by unSpawn towards the top of the forum. Go through the Compromise, breach of security, detection section and specifically at the CERT intrusion detection checklist. You should also take the machine in question offline until you are sure that it has not been compromised.
 
Old 04-27-2004, 10:35 AM   #6
KooPA
Member
 
Registered: Apr 2004
Location: Phili
Distribution: SuSE v9.1 Personal, Slackware (TV Server)
Posts: 53

Original Poster
Rep: Reputation: 15
Thanks alot caveman, will check it out tonight.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
libpng flaw rgiggs Slackware 4 08-06-2004 04:57 AM
Flaw in kernel 2.4.26 gstasica Linux - General 3 07-16-2004 04:27 PM
a flaw is just a flaw jamaso General 1 03-25-2003 07:45 AM
Is this a Linux security flaw ? josedsilva Linux - Security 3 05-24-2002 01:03 AM
wu-ftpd :serious flaw anoop_chandran Linux - General 3 12-11-2001 03:36 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:48 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration