LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 11-21-2004, 04:31 PM   #1
phiberoptik
LQ Newbie
 
Registered: Nov 2004
Posts: 13

Rep: Reputation: 0
Kill a user off line


Phiber Optik's again i have some "unwanted" users on my computer tyring to get into my root account... now what means would i go about to kill or kick this user offline... please help ASAP!!!!
 
Old 11-21-2004, 04:36 PM   #2
mdarby
Member
 
Registered: Nov 2004
Location: Columbus, Ohio
Distribution: Slackware-Current / Debian
Posts: 795

Rep: Reputation: 30
killing a user offline sounds rather illegal.
 
Old 11-21-2004, 04:37 PM   #3
phiberoptik
LQ Newbie
 
Registered: Nov 2004
Posts: 13

Original Poster
Rep: Reputation: 0
um.... not in that sence... i own the linux box.... i dont know who this person is whom that is logged in.... how do i kick them off my linux box without restarting or pulling the internet plug???
 
Old 11-21-2004, 04:42 PM   #4
egag
Senior Member
 
Registered: Jul 2004
Location: Netherlands
Distribution: Slackware
Posts: 2,721

Rep: Reputation: 53
if you know their IP-nr.'s ( might be in /var/log/messages ) you can put those in " /etc/hosts.deny. "

egag
 
Old 11-21-2004, 04:46 PM   #5
phiberoptik
LQ Newbie
 
Registered: Nov 2004
Posts: 13

Original Poster
Rep: Reputation: 0
hm.... i see.... i like your idea but unfortunently he has multiple computers and is currently at friends houses with a BUNCH of hackers... he says that he is at home on SSH but i dont know if i can believe him just yet.... regardles thanks a lot man... and if you have AIM, or GAIM IM me paintballMC117
 
Old 11-21-2004, 05:29 PM   #6
mdarby
Member
 
Registered: Nov 2004
Location: Columbus, Ohio
Distribution: Slackware-Current / Debian
Posts: 795

Rep: Reputation: 30
Why not kill sshd?
 
Old 11-21-2004, 06:13 PM   #7
Krugger
Member
 
Registered: Oct 2004
Posts: 229

Rep: Reputation: 30
Just kick them out. You are using slackware and you aren't rigged up...

1- Log in as root.
su
2- Kick everyone out. This kill all processes not owned by root,daemon, nobody and gdm
pkill -v -u root,daemon,nobody,gdm
3- Keep them out.
iptables -P INPUT DROP
iptables -P INPUT FORWARD DROP
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT

Put these iptable rules in your firewall and they can't touch you.

Now you have to rebuild the kernel and start the cleaning process. Newer know if a backdoor is installed.


Then it's time for pay back. ;-)
 
Old 11-21-2004, 06:15 PM   #8
Krugger
Member
 
Registered: Oct 2004
Posts: 229

Rep: Reputation: 30
Oh if it is only 1 user

pkill -u user and all his processes die.
 
Old 11-21-2004, 06:36 PM   #9
Krugger
Member
 
Registered: Oct 2004
Posts: 229

Rep: Reputation: 30
Oh and change your passwords for the affected user accounts.

Just wanted to remind that you have their IPs from the logs.

So...

There are 3 choices
- complain to someone, police(delete your warez first)
- retaliation (don't expect help with it here)
- learn more about how to defend your self
 
Old 11-24-2004, 06:29 PM   #10
phiberoptik
LQ Newbie
 
Registered: Nov 2004
Posts: 13

Original Poster
Rep: Reputation: 0
hey Krugger you RULE please if you have AIM im me at paintballMC117 thanks!!!!
 
Old 11-24-2004, 07:10 PM   #11
ringwraith
Senior Member
 
Registered: Sep 2003
Location: Indiana
Distribution: Slackware 15.0
Posts: 1,272

Rep: Reputation: 65
If you're really phiberoptik shouldn't you already know all of this ;-)
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to kill an idle user via the command line? goemon Linux - General 7 12-01-2005 06:01 PM
Please dont kill me for asking.. Command line? (I AM i n00b) Nox_hand Linux - Newbie 17 09-17-2005 03:59 PM
How can I see what process are running and how to I kill them? (command line). brynjarh Linux - Newbie 4 07-07-2004 03:01 PM
kill program command line demmylls Linux - General 7 02-09-2004 08:55 PM
one-line kill command using process name julianop Linux - Newbie 6 12-22-2003 11:33 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 06:30 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration