LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > SUSE / openSUSE
User Name
Password
SUSE / openSUSE This Forum is for the discussion of Suse Linux.

Notices


Reply
  Search this Thread
Old 10-29-2004, 09:35 PM   #1
oily_rags
Member
 
Registered: Sep 2004
Posts: 128

Rep: Reputation: 15
susefirewall2 and seeing intruders


my friend claims he hacked me, as a joke, don't know if he's serious or not, but it got me thinking, I never considered looking at the firewall logs before.
I checked them out but i'm not sure which ones are actually the firewall logs and in the logs, what to I look for that indicates an attack or someone probing my machine?
I am not sure and it would be good to know this information. I am using suse 9.1. Thanks
 
Old 10-31-2004, 12:00 AM   #2
m_shroom
Member
 
Registered: Oct 2004
Location: Queen Charlotte B. C. Canada
Distribution: openSUSE 11.1
Posts: 42

Rep: Reputation: 15
Are You running Susefirewall2 in with all it's default settings and have you selected the correct external interface ?
--- If yes your friend is pulling your leg unless you have an internal wireless lan.
-- else post your firewall settings

Firewall logs can be found in " /var/log/messages " but with out extra logging turned on there may be nothing there to find.

With an always on connection;
Logging all dropped packets will generate at least 500 lines a day some times many 1000's depending on virus & worm activity
Logging all packets will generate all of the above + your activity + what ever ( in short will log everything to and from )

I run with "Log all dropped packets" and forward my logs to http://www.dshield.org/ in an effort to clean up the net.
 
Old 10-31-2004, 10:59 AM   #3
oily_rags
Member
 
Registered: Sep 2004
Posts: 128

Original Poster
Rep: Reputation: 15
thanks for the info m_shroom. I do have the firewall set on it's default settings. In your opinion is it a good firewall? I know this is subjective but I was wondering what your opinion is, I see very little discussion on this firewall. I got no internal network runnin, so that makes me less vulnerable? anyhow thanks for the response
 
Old 10-31-2004, 09:12 PM   #4
m_shroom
Member
 
Registered: Oct 2004
Location: Queen Charlotte B. C. Canada
Distribution: openSUSE 11.1
Posts: 42

Rep: Reputation: 15
If you have down loaded and installed all of the security updates from SuSE (on-line update) your system would be very hard to hack, with Susefirewall2 running in its default configuration ( all ports closed or hidden ) it's all but impossible to hack over the net
 
Old 11-01-2004, 02:11 PM   #5
Sabicas
Member
 
Registered: Aug 2004
Distribution: Slackware 10
Posts: 110

Rep: Reputation: 15
Yeah, SuSE firewall's actually pretty good. The logging issue bothered me though. If you read through your root mail (either after install or after a SuSE firewall update I can't remember it's been a while), you'll find that they opted to turn firewall syslog off.

The mail will instruct you on how to edit the syslog file and what to do to turn the firewall log back on.

I posted a how to on this issue a while ago on this site if you search you'll probably find it.

Is your friend running windows?
 
Old 11-01-2004, 03:27 PM   #6
oily_rags
Member
 
Registered: Sep 2004
Posts: 128

Original Poster
Rep: Reputation: 15
yeah he's running windows, i'm pretty confident that suse is hard to crack but still, I used to use sygate firewall in windows and i liked it's alerts, it showed graphically and in logs if people were doing port scans and whatnot, if there were major intrusions
 
Old 11-01-2004, 07:21 PM   #7
Adler
Member
 
Registered: Oct 2004
Location: Wildwood, NJ
Distribution: Debian Jessie
Posts: 192

Rep: Reputation: 18
Is there a GUI out there that can be launched in Linux?

I have the usual set of GUIs for f-prot (my virus scanner), Synaptic (my Suse apt-get up-dater), etc.

I think the idea boils down to showing some type of "real-time" intrusion detection that can alert someone that he has just been "attacked / hacked".
 
Old 12-28-2004, 02:33 PM   #8
oily_rags
Member
 
Registered: Sep 2004
Posts: 128

Original Poster
Rep: Reputation: 15
exactly, I was hoped that I could have a graph show intrusion attempts running in the taskbar that i can goto, instead of having to comb through logs at some later date. If someone is hammering my PC with intrusion attempts I want to know about it and where the ip is coming from.
 
Old 01-04-2005, 02:13 AM   #9
gbj
Member
 
Registered: Jul 2003
Posts: 142

Rep: Reputation: 15
So has anyone found a real-time intrusion detection software that runs well on suse, preferably with a nice gui? It would be nice to know if some script kiddie is trying to hack his way into the system...
 
Old 01-27-2005, 09:50 AM   #10
69_rs_ss
Member
 
Registered: Jan 2004
Location: NY, USA
Distribution: Arch, openSUSE 11.1
Posts: 170

Rep: Reputation: 31
Check out Snort which is a realtime IDS that can be used in conjunction with MySQL, Apache and PHP.
 
Old 12-14-2005, 07:25 PM   #11
mazinoz
Member
 
Registered: Mar 2003
Location: Mansfield Queensland Australia
Distribution: Linux Mint - Tara
Posts: 497

Rep: Reputation: 35
Also look at tripwire
 
Old 12-15-2005, 06:05 PM   #12
fragos
Senior Member
 
Registered: May 2004
Location: Fresno CA USA
Distribution: Ubuntu 10.10
Posts: 1,466

Rep: Reputation: 51
Windows user hacking into a Linux system smells pretty fishy to me.
 
Old 12-17-2005, 12:22 AM   #13
crazibri
Member
 
Registered: Mar 2004
Location: Orange County, CA
Distribution: OS X, SuSE, RH, Debian, XP
Posts: 377

Rep: Reputation: 31
Yeah smells fishy to me too.

If anything use your Synaptic to find Nessus. I'm sure if you use Nessus and set it up right, you can scan your friend and tell him what's wrong with his Windows machine
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
SuseFirewall2 XaViaR SUSE / openSUSE 4 06-02-2005 10:40 PM
tracking intruders bishal Linux - Security 1 08-14-2004 07:12 AM
susefirewall2 gazza Linux - Newbie 2 04-05-2004 01:22 AM
SuSEfirewall2 cdeorla Linux - Security 4 09-21-2003 07:09 PM
Microsoft’s network is hacked - Intruders believed to have stolen code for software jeremy General 3 11-26-2000 08:21 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > SUSE / openSUSE

All times are GMT -5. The time now is 03:58 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration