Linux Help
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsOperating SystemsLinux Help

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
Stop making mediocre tutorials.The best tutorials are video! Camtasia Studio makes it easy to create engaging, buzz-building screen videos at any size, in any popular format. Download the free trial!
  #1  
Old July 31st, 2002, 09:26 PM
StealthElephant's Avatar
StealthElephant StealthElephant is offline
Shes dancing (obviously)
Dev Shed Novice (500 - 999 posts)
 
Join Date: Jul 2002
Location: the far side
Posts: 526 StealthElephant User rank is Corporal (100 - 500 Reputation Level)StealthElephant User rank is Corporal (100 - 500 Reputation Level)StealthElephant User rank is Corporal (100 - 500 Reputation Level)StealthElephant User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 2 h 14 m 22 sec
Reputation Power: 8
Security tips here!

I have a good security tip if anyone doesnt already know it:
If someone reboots your machine they can type linux 1 (single user) and get root access to your machine, to over come this edit the /etc/inttab file and instruct the system to run the sulogin command by entering the following
su:s:wait:/sbin/sulogin
this however still lets the user boot the system but not get anywhere,
LILO can also be changed to prevent this,
if paramaters are given to LILO, it can instruct to ask for a password, put the following lines in

image=/boot/vmlinux
..........
..........
restricted
password=Mypassword

other=/dev/fd0
.............
............

your lilo file obviously needs to be nonreadable then to other users, restricted keyword can be placed in other places which also prevents someone comming along with a boot disk and getting access that way.

Is there any hacking counter measures that can be takin for these tips? if so please post here and let me know.
Likewise, if you have any other security tips, please post here and educate
__________________

microsofts butterfly is their way off telling u their systems have a **** load of buggs
Advocating Linux Guide
Lesbian Linux
Great & Practical Computer Books

like the links?

Reply With Quote
  #2  
Old August 1st, 2002, 04:40 PM
M.Hirsch M.Hirsch is offline
Contributing User
Dev Shed God 1st Plane (5500 - 5999 posts)
 
Join Date: Oct 2000
Location: Back in the real world.
Posts: 5,969 M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level) 
Time spent in forums: 1 Month 1 Day 22 h 39 m 55 sec
Reputation Power: 184
sorry, but i think this is the wrong place to discuss this. this forum is about programming, not cracking.

there is ways to circumvent anything. the only secure machine is one that is powered off and inside a safe. even then there is ways to get in...

my linux distro still asks for the root password if i boot into runlevel 1 or S. but the actual hack you refer to is:
lilo: linux init=/bin/sh
which gives you root access without password. but there is 1000s others. to make a secure system, you need a lot more knowledge about security...

Quote:
which also prevents someone comming along with a boot disk and getting access that way

wrong. a bootdisk works independent of your haddisk setup. you need to setup boot device to be ONLY harddisk and password-protect the bios to prevent bootdisks. even better, encrypt the whole harddisk. bet even then i can get in anyway?
and: did you know that there is standard-passwords for nearly every bios?
did you know that you only need a few 100 tries to hack any bios password since they donīt store the complete password but a two-byte hash? take a hardware that simulates key-presses to test 1000s in a few minutes, eg. connect the keyboard port to a notebookīs com/lpt port.
Quote:
your lilo file obviously needs to be nonreadable then to other users

obviously no system configuration file should.

for further reference, visit:
www.cert.org
and get onto your linux distributorīs security mailing list. and also on redhatīs and suseīs.

and i wonīt post any other urls. please donīt ask.

greetings,
M
__________________
--
Manuel Hirsch - Linux, FreeBSD, programming, administration articles, tutorials and more.

Reply With Quote
  #3  
Old August 1st, 2002, 05:16 PM
StealthElephant's Avatar
StealthElephant StealthElephant is offline
Shes dancing (obviously)
Dev Shed Novice (500 - 999 posts)
 
Join Date: Jul 2002
Location: the far side
Posts: 526 StealthElephant User rank is Corporal (100 - 500 Reputation Level)StealthElephant User rank is Corporal (100 - 500 Reputation Level)StealthElephant User rank is Corporal (100 - 500 Reputation Level)StealthElephant User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 2 h 14 m 22 sec
Reputation Power: 8
is this not the linux forum? there is others forums here for programming and algorithims, whats the harm in trying to find out how secure a machine against crackers?

Reply With Quote
  #4  
Old August 2nd, 2002, 12:24 AM
M.Hirsch M.Hirsch is offline
Contributing User
Dev Shed God 1st Plane (5500 - 5999 posts)
 
Join Date: Oct 2000
Location: Back in the real world.
Posts: 5,969 M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level) 
Time spent in forums: 1 Month 1 Day 22 h 39 m 55 sec
Reputation Power: 184
i wanted to express that there is probably few security experts here, so you better ask in a security mailing list or board.

there is a several 100 security tips on the url i told you and these guys are supposed to be among the best experts about security.

if you have a specific question, no problem.

i just donīt want you (and the others here) to get a false impression about security. this isnīt done with a few tips that we can put here over the next weeks... security is a full-time job and has to be done completely or is of no use at all. one single hole you leave open and over short time, somebody will find it.

which distro are you using that has such a bad pre-configuration
(no password in single user mode)?

Reply With Quote
  #5  
Old August 2nd, 2002, 12:51 AM
StealthElephant's Avatar
StealthElephant StealthElephant is offline
Shes dancing (obviously)
Dev Shed Novice (500 - 999 posts)
 
Join Date: Jul 2002
Location: the far side
Posts: 526 StealthElephant User rank is Corporal (100 - 500 Reputation Level)StealthElephant User rank is Corporal (100 - 500 Reputation Level)StealthElephant User rank is Corporal (100 - 500 Reputation Level)StealthElephant User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 2 h 14 m 22 sec
Reputation Power: 8
cough cough, mandrake 7 , i was just wondering through the files and saw a badly configured lilo and inttab, i checked out your link, very interesting - thank you

Reply With Quote
  #6  
Old August 2nd, 2002, 05:09 AM
telex4's Avatar
telex4 telex4 is offline
Wacky hack
Dev Shed Novice (500 - 999 posts)
 
Join Date: Apr 2001
Location: London, England
Posts: 512 telex4 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 h 25 m 29 sec
Reputation Power: 8
At the end of the day, if someone has physical access to your box, you're screwed anyway They could just take the hard drive out, mount it on a different box, and they've got all your data. Likewise they could use a boot floppy / cd to boot a system up then remove your protection by mounting the hard drive to a temporary place. Therefore the best security tip is to put a BIOS password on the machine, lock the case if possible, and hide it away somewhere, and use a different box to get remote access (assuming its a server we're talking about).

Reply With Quote
  #7  
Old August 3rd, 2002, 11:49 AM
M.Hirsch M.Hirsch is offline
Contributing User
Dev Shed God 1st Plane (5500 - 5999 posts)
 
Join Date: Oct 2000
Location: Back in the real world.
Posts: 5,969 M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level) 
Time spent in forums: 1 Month 1 Day 22 h 39 m 55 sec
Reputation Power: 184
an interesting thread about security in php:
http://forums.devshed.com/showthread.php?threadid=20525
you see, security has many many more aspects than only OS security

Reply With Quote
Reply

Viewing: Dev Shed ForumsOperating SystemsLinux Help > Security tips here!


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 3 hosted by Hostway