Webmaster Forums - Webmaster forum for HTML, PHP, ASP, CSS and more

Go Back   Webmaster Forums - Webmaster forum for HTML, PHP, ASP, CSS and more > Linux Operating System > Web/Security
User Name
Password

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
Old 09-23-2005, 04:47 AM   #1 (permalink)
kamal
Junior Member
 
Join Date: Sep 2005
Posts: 3
Default Newbie security problem

WHat do you guys check for intrusion and hackers? I am getting strange things in my /tmp folder these days and those programs in it are linked back to some IRC relay thing... Am I being hacked?
kamal is offline   Reply With Quote
Sponsored Links
Old 09-24-2005, 01:46 PM   #2 (permalink)
cornelis
Member
 
Join Date: Sep 2005
Posts: 62
Default

You can try to install a hardware firewall to block specific ports so even if a hacker gets in he still can't use it because opening ports in the server will be useless as it will be blocked at firewall level.
cornelis is offline   Reply With Quote
Old 09-24-2005, 07:44 PM   #3 (permalink)
clifford
Junior Member
 
Join Date: Jun 2005
Location: Finland
Posts: 26
Default

I have used snort to check for intrusions and exploits. It's a pretty cool tool.
http://www.snort.org/

You may find some other good ones here:
http://www.hackinglinuxexposed.com/resources/
clifford is offline   Reply With Quote
Old 08-12-2006, 08:01 PM   #4 (permalink)
Shadow
Junior Member
 
Join Date: Aug 2006
Posts: 65
Default Re: Newbie security problem

get a hardware firewall
Shadow is offline   Reply With Quote
Old 08-17-2006, 01:36 PM   #5 (permalink)
mrswampy
Junior Member
 
Join Date: Aug 2006
Posts: 9
Default Re: Newbie security problem

Are software firewalls no use then?
mrswampy is offline   Reply With Quote
Old 08-18-2006, 08:03 PM   #6 (permalink)
apcbill
Junior Member
 
Join Date: Aug 2006
Location: KC
Posts: 4
Default Re: Newbie security problem

Software firewalls are just as good when implemented correctly. And if you think about it a hardware firewall has software running on it. So it is still a software firewall.

Look into using Netfilter(IPtables) most current distros have the firewall on them and an easy gui if you don't want to learn the command line.

As for detecting intrusions. There are alot of different ways to check. A good way is to setup the Netfilter firewall and then check for incoming and outgoing connections that didn't originate from you.

Snort is also a good tool to use to observe network intrusions. It may be too advanced for someone with limited security or networking knowledge.

You can also use the netstat -an command to look at current connections if you know what you're looking for and you haven't been rootkitted.

If you would like I could look at your sytem for you. But you don't know me. The only thing I can offer as credentials is my CISSP number. It is a professional certification that requires me to not hack/crack where not asked to.

Good luck.
apcbill is offline   Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Points Per Thread View: 1.00
Points Per Thread: 11.00
Points Per Reply: 5.00



» Sponsors

» Links

» Affiliates
Web Hosting
Online Backup Reviews
Marketing Find
Merchant Select
SiteMap Builder
Host Compare
Dedicated Servers

» Links

» Sports Network
Paintball Forum
Football Forum
Hockey Forum
Golf Forum
Boxing Forum
Lacrosse Forum
Baseball Forum
SnowBoarding Forum
Soccer Forum
MMA Forum


All times are GMT -4. The time now is 03:37 PM.



LinkBacks Enabled by vBSEO 3.0.0 RC8
Webmaster Forums