The UNIX and Linux Forums  

Go Back   The UNIX and Linux Forums > Top Forums > UNIX for Dummies Questions & Answers
.
google unix.com



UNIX for Dummies Questions & Answers If you're not sure where to post a UNIX or Linux question, post it here. All UNIX and Linux newbies welcome !!

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
Any backdoors? jellegard UNIX for Advanced & Expert Users 7 10-08-2003 01:39 PM

Closed Thread
English Japanese Spanish French German Portuguese Italian Dutch Swedish Russian Norwegian Hungarian Hebrew Danish Bulgarian Greek Powered by Powered by Google
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
  #1 (permalink)  
Old 01-07-2003
skotapal skotapal is offline
Registered User
  
 

Join Date: Aug 2002
Location: Philadelphia, PA
Posts: 75
Backdoors etc

Hi all
Is there a way I can detect and monitor backdoors that may be present on a system? I want to see how users can come in and if possible log their IPs and ban them from the system altogether.

Also, is there a way other than cron and at to have a script start off a program? I can see a process coming up but cannot find out how it is starting up again and again.

Much appciated....


KS
  #2 (permalink)  
Old 01-07-2003
RTM's Avatar
RTM RTM is offline Forum Advisor  
Hog Hunter
  
 

Join Date: Apr 2002
Location: On my motorcycle
Posts: 3,039
One way - It could be in the init file - look at /etc/inittab - entries can be added to respawn when a process dies.

If you don't have an inittab, post the OS you are using.
  #3 (permalink)  
Old 01-07-2003
hugo_perez hugo_perez is offline
Registered User
  
 

Join Date: Apr 2002
Location: Argentine - that better than to eat meat and to drink wine (both Argentineans)?.
Posts: 132
lost cause.

Back doors in several cases are programming errors,
the most common reaction is the corrective reaction.
My suggestion is to disable all services that you don't use.

There are several programs to check if you have the
latest patches in your system, some freewares and
others no.

In the last category I prefer ESM (Enterprise Security
Manager from Symantec _previusly from axent_), but there
are severals for example the SAFEsuite has more integration.
These tools are multiplatform and centralized.

In the other hand depend on your OS.


Please POST your OS an the program name.

Regards. Hugo.
  #4 (permalink)  
Old 01-07-2003
skotapal skotapal is offline
Registered User
  
 

Join Date: Aug 2002
Location: Philadelphia, PA
Posts: 75
My OS is Redhat Linux 7.3. The respawnning process is vbox.
  #5 (permalink)  
Old 01-07-2003
hugo_perez hugo_perez is offline
Registered User
  
 

Join Date: Apr 2002
Location: Argentine - that better than to eat meat and to drink wine (both Argentineans)?.
Posts: 132
Are you using GTK or ISDN?

If you are using ISDN or GTK is normal.

If ISDN look at /etc/isdn

Regards. Hugo.
  #6 (permalink)  
Old 01-07-2003
skotapal skotapal is offline
Registered User
  
 

Join Date: Aug 2002
Location: Philadelphia, PA
Posts: 75
no, not using GTK or ISDN? What are they used for? I did see /etc/isdn and am looking into it at the moment.
  #7 (permalink)  
Old 01-07-2003
LivinFree's Avatar
LivinFree LivinFree is offline Forum Advisor  
Goober Extraordinaire
  
 

Join Date: Jul 2001
Location: Portland, OR, USA
Posts: 1,584
If you're not using isdn, you can uninstall the isdn* RPMs.
vbox is the name of a program included with ISDN utilities.
Closed Thread

Bookmarks

Tags
linux

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT -4. The time now is 08:23 AM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited. Language Translations Powered by .
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios
The UNIX and Linux Forums Content Copyright ©1993-2009. All Rights Reserved.Ad Management by RedTyger

Content Relevant URLs by vBSEO 3.2.0