Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Security and Privacy
FedoraForum Search

Forgot Password? Join Us!

Security and Privacy Sadly, malware, spyware, hackers and privacy threats abound in today's world. Let's be paranoid and secure our penguins, and slam the doors on privacy exploits.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 27th August 2007, 07:30 PM
rbhkamal Offline
Registered User
 
Join Date: Jul 2007
Posts: 34
Getting hacked.... need help!!!

Hi all,
Few days ago I set up an ocsp server using openssl; that service was running as ROOT all the time...
Today I noticed that the server is not responding to some of my ocsp requests. So I started the sniffer to see what the hell is going on. It turned out that someone from Japan is trying to hack my server using port 80 (OCSP).

What should I do next? Should I create a dedicated user and group for that service? if so can someone help me out?

I really need help on this one. please

Regards,
RK
Reply With Quote
  #2  
Old 27th August 2007, 09:08 PM
artiomix Offline
Registered User
 
Join Date: Aug 2007
Posts: 2
There are some recommendations that are to be done first:

1) get ocsp server running under regular user (if it's possible of course)
2) get ocsp server running in chroot (use google for more information)
3) change ocsp port from 80 port to some other one
4) block suspected IP addresses with iptables:
iptables -A INPUT -s 123.45.67.89 -j DROP

Hope it helps.
Reply With Quote
  #3  
Old 29th August 2007, 03:39 PM
rbhkamal Offline
Registered User
 
Join Date: Jul 2007
Posts: 34
Thanks, I'm still working on it.
That dumass keeps changing his source IP address.... he's probably using a proxy.
Reply With Quote
  #4  
Old 31st August 2007, 02:58 AM
Zotter's Avatar
Zotter Offline
Registered User
 
Join Date: May 2004
Location: Central Wyoming
Posts: 637
If it's port 80 attacks - it's likely from all over the place. Common scan port, bot port, mal ware port.

If you've never run a server on 80 before, it can be a bit surprising to see the volume of attack traffic - but, sadly, it's rather normal.

taken a look at mod_security yet? http://www.modsecurity.org/
__________________
If it ain't broken - you're not really trying....
Registered Linux user #227845
Reply With Quote
  #5  
Old 8th September 2007, 07:56 PM
rbhkamal Offline
Registered User
 
Join Date: Jul 2007
Posts: 34
Thanks for the link, I didn't know about this.
My OCSP server is done using openssl ocsp and not Apache. Will it still work?

I've already tried chroot jail and I feel a little safer, but there is always room for more security
Reply With Quote
  #6  
Old 9th September 2007, 09:57 AM
Crito Offline
Registered User
 
Join Date: Aug 2007
Location: Knoxville, TN
Posts: 256
Quote:
Originally Posted by rbhkamal
.. but there is always room for more security
In that case you should enclose your computer in concrete and sink it to the bottom of the ocean.

Security is a balancing act with usability; the more of one you have the less of the other.
__________________
How to Block Google Spyware
"They're going to sell it to us as a security system -- they may even have convinced themselves it will improve security -- but it's fundamentally a control system." - Bruce Schneier
Reply With Quote
  #7  
Old 10th September 2007, 03:54 AM
Firewing1's Avatar
Firewing1 Offline
Administrator
 
Join Date: Dec 2004
Location: Canada
Age: 22
Posts: 9,224
Code:
yum install mod_ssl mod_security pam_tally
Firewing1
__________________
[+] My open source software and blog
[+] Some of my howtos: (for full list, click here)
Reply With Quote
  #8  
Old 10th September 2007, 06:30 AM
rbhkamal Offline
Registered User
 
Join Date: Jul 2007
Posts: 34
Thanks, I'll try it out first thing Monday.

btw
Any other cool ideas on securing web servers? Something new?

Regards,
RK
Reply With Quote
  #9  
Old 10th September 2007, 07:05 AM
rbhkamal Offline
Registered User
 
Join Date: Jul 2007
Posts: 34
I'm going to install DenyHosts as well
Reply With Quote
Reply

Tags
hacked

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Am I being hacked? doctorwhite Security and Privacy 11 6th January 2009 07:21 PM
I got hacked tabish121 Security and Privacy 9 17th October 2006 10:59 AM
Hacked? wgh Servers & Networking 6 31st May 2006 10:44 PM
i got hacked...help! mvalcarcel Security and Privacy 3 27th May 2006 02:46 PM


Current GMT-time: 03:58 (Monday, 20-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat