»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 06-26-2003, 09:48 AM   #1 (permalink)
Registered User
 
Join Date: Jun 2003
Posts: 3
mikelo2k is on a distinguished road
Gaming Securing a fresh redhat install...

Hello everyone, I was recently given root access to a box by a friend, so that i could setup some web-services and ftp acess. Well, i logged in, and i found that it had been 'r00ted' by '31337 h4x0rz' more than once ;/ So i traced the one guy via his bot to one server, didnt say anything, just removed the accounts he made, so now all thats left is root. And i changed roots password.

Now the thing is, im pretty sure there is a backdoor, and the deamon they prolly exploited is still running ;/ (there were like 1000 processes running on this lil P2).

My idea, is to format and re-install RedHat v9, but this time i wanna tell my friend what he needs and doesnt need to install. And i would like to make sure that ONLY ssh, is the only thing that should auto-run on the box when its started. And nothing in CRON either.


So really my question is, could someone please point me to a tutorial that would guide me to do a clean RedHat install w/nothing in the CRONTRAB auto-run files, and only SSH running?




Thank you very much,
Mikelo2k

mikelo2k is offline   Reply With Quote
Old 06-26-2003, 10:13 AM   #2 (permalink)
Registered User
 
crouse's Avatar
 
Join Date: Jun 2002
Location: Iowa
Posts: 2,527
crouse is on a distinguished road
Send a message via ICQ to crouse
I have a few security links here http://www.usalug.org/phplinks/index.php?PID=71

Not sure if they have what your looking for or not.
Might also check www.chrootkit.org
__________________
The day Microsoft makes something that doesn't suck is probably the day they start making vacuum cleaners. --- Author Unknown.
crouse is offline   Reply With Quote
Old 06-26-2003, 10:29 AM   #3 (permalink)
Registered User
 
Join Date: Jun 2003
Posts: 3
mikelo2k is on a distinguished road
Thanks, ill check em out!
mikelo2k is offline   Reply With Quote
Old 06-26-2003, 11:51 PM   #4 (permalink)
Registered User
 
crouse's Avatar
 
Join Date: Jun 2002
Location: Iowa
Posts: 2,527
crouse is on a distinguished road
Send a message via ICQ to crouse
I kept looking
A quick guide to installing and securing Red Hat Linux in less than an hour
http://www-106.ibm.com/developerwork...-lnxw99RedHat8

Hows that ??
__________________
The day Microsoft makes something that doesn't suck is probably the day they start making vacuum cleaners. --- Author Unknown.
crouse is offline   Reply With Quote
Old 06-27-2003, 10:07 AM   #5 (permalink)
Registered User
 
Join Date: Jun 2003
Posts: 3
mikelo2k is on a distinguished road
Talk

Sweet! Thats perfect!!

Thanks alot dude
mikelo2k is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 04:19 AM.