Welcome to Linux Forums! With a comprehensive Linux Forum, information on various types of Linux software and many Linux Reviews articles, we have all the knowledge you need a click away, or accessible via our knowledgeable members.
Write an article for LinuxForums Today! Win Great Prizes!
Find the answer to your Linux question:
New to Linux Forums? Register here for free!
    Linux Forums > GNU Linux Zone > Linux Security > compromised

Forgot Password?
 Linux Security   Discussion about keeping your machines secure, and the crackers out.

Site Navigation
Linux Articles
Linux Forums
Linux Downloads
Linux Hosting
Free Magazines
Job Board
IRC Chat
RSS Feeds
Linux Forum Topics
Linux Forums
Your Distro
Linux Resources
GNU Linux Zone
The Community
Reply
 
Thread Tools Display Modes
Old 04-30-2005   #1 (permalink)
Just Joined!
 
Join Date: Apr 2005
Posts: 7
compromised

When a file shows an 'accessed' time at some-time when I'm not around - that means something is not ok, right? (suse 9.2 konquerer)

5 files all show access time of 7:02pm. None of which I have touched since noon that day. Room is locked, and screensaver locked session.

Suse 9.2. updated as far as that SuSE YAST Online tells me that it is.
Installed nothing apart from what came on the distro dvd. ( its got everything I needed )

Runlevel has:
xdm, syslog, SuSEfirewall, splash early, splash, smpppd, running-kernel, resmgr, random, portmap, nscd, nfs ( but not configured & not used ), network, kbd, hwscan, fbset, cups, cron.

I followed the simple rules, install nothing, disable listening services, run the online update frequently.

Well, I wasnt watching the Compromised News Network and patching religiously as per suse alerts. But I assumed the SuSE Online Update thing was a within-next-couple-of-days-butler-service

This box survived less than 1 month? Isnt that below average? (but I'm new to this badge vs hack game )

Yes, I already know I need to win the lottery and hire a security team to monitor my home boxes

Any suggestions as to where the entry point is? From what little I know about linux, the only listening service up there in that list is the dns cache - nscd.

Any suggestions for a locked down distro - free ones - that is?
i-only-know-dos is offline  



Reply With Quote
Old 04-30-2005   #2 (permalink)
Linux Guru
 
Join Date: Apr 2003
Location: London, UK
Posts: 3,284
a changed file accessed time is NOT any indication whatsoever that you have been hacked. What file was it? were there any cron jobs running that read the file? any running programs that may have accessed it? ...
jasonlambert is offline   Reply With Quote
Old 04-30-2005   #3 (permalink)
Just Joined!
 
Join Date: Apr 2005
Posts: 7
Hi ,

The file was is a pdf document downloaded around noon time - which I did not read or touch.

No scheduled jobs were ever done - clean machine.

Among the other files accessed was a bookmark file in which I wrote down which chapter I was reading in several books. The info is dated and I did not ever open it after initial create.

What could modify a file's accessed time ? Other than a read ?
i-only-know-dos is offline   Reply With Quote
Old 04-30-2005   #4 (permalink)
Linux Engineer
 
Join Date: Sep 2003
Location: Knoxhell, TN
Posts: 1,078
Send a message via MSN to lordnothing
touch(1) can change a file's mtime... some bg proc accessing it can change the mtime, etc.
__________________
Their code will be beautiful, even if their desks are buried in 3 feet of crap. - esr
lordnothing is offline   Reply With Quote
Old 04-30-2005   #5 (permalink)
Just Joined!
 
Join Date: Apr 2005
Posts: 7
I don't understand what 'some big proc" means ? What process are you thinking of? Or did you mean buggy process ?

Reason my spidy senses tingled is because my win2k box rebooted itself and after that, my account is denied logon. So .... I check my other boxes for signs.
i-only-know-dos is offline   Reply With Quote
Old 04-30-2005   #6 (permalink)
Just Joined!
 
Join Date: Apr 2005
Posts: 7
but since this is not a windows forum. I didnt want to mention that here.
i-only-know-dos is offline   Reply With Quote
Old 05-01-2005   #7 (permalink)
Just Joined!
 
Join Date: Apr 2005
Posts: 7
Hi lordnothing,

Ok. Now I know what bg is. Which goes to show that I dont even know how to suspend a job before, ruling out the bg as a cause. I don't didnt use touch either. So that eliminates two probable causes. No cron jobs here either.

Anyone care to give me more causes as to why the access time stamps are modified ?

If the access time stamp does not indicate a READ, then what does it indicate? This is that capital C that I need to maintain, right? I need to understand this for this box. Please point me to some documentation/book/manual.
i-only-know-dos is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Free Magazines
A Newbie's Getting Started Guide to Linux
Learn the basics of the Linux operating systems. Get to know what it is all about, and familiarize yourself with the practical side. Basically, if you're a complete Linux newbie and looking for a quick and easy guide to get you started this is it.
subscribe
Run Your Own Web Server Using Linux & Apache - Free 191 Page Preview
Learn about everything you'll need to build and maintain your Linux servers, and to deploy Web applications to them.
subscribe
Open Source Security Myths Dispelled
Dispel the five major myths surrounding Open Source Security and gain the tools necessary to make a truly informed decision for your IT organization
subscribe
InformationWeek
InformationWeek is the only newsweekly you'll need to stay on top of the latest developments in information technology.
subscribe



All times are GMT. The time now is 02:25 PM.






© 2000 - - All Rights Reserved - Property of  MAS Media

Content Relevant URLs by vBSEO 3.3.1