Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Community Lounge > Wibble
FedoraForum Search

Forgot Password? Join Us!

Wibble A place to have a sensible chat, about anything non linux related. Please remember that political and religious topics are not permitted.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 24th November 2008, 03:25 AM
kevaljd Offline
Registered User
 
Join Date: Jul 2008
Location: London
Posts: 77
Question Linux hack

My friend demonstrated linux loopholes (which he never told me)
he just asked my IP address, I gave.

Chk what happened next:

http://i38.tinypic.com/2r5uy3d.jpg

ps aux displayed no other processes than the once going in my logic...
He mentioned something related to sshd, now what is that, i dunno!

Chk the upload speed.... I never got download speed this much!
__________________
Keval Domadia

Suspense behind each distro is:
................ tell you later!

Last edited by kevaljd; 24th November 2008 at 03:34 AM.
Reply With Quote
  #2  
Old 24th November 2008, 03:28 AM
Demz
Guest
 
Posts: n/a
thats called advertising IMO,, you should know thats not allowed on the forum
Reply With Quote
  #3  
Old 24th November 2008, 03:32 AM
kevaljd Offline
Registered User
 
Join Date: Jul 2008
Location: London
Posts: 77
Hey Demz..
There seems to be a misunderstanding...
I thought I would attach file on my hosting site and then share it... but it just aint workin seriously got no idea... will edit it in a bit.....


EDIT:
DONE! Now u can chk the link above and see it urself
__________________
Keval Domadia

Suspense behind each distro is:
................ tell you later!

Last edited by kevaljd; 24th November 2008 at 03:36 AM.
Reply With Quote
  #4  
Old 24th November 2008, 03:36 AM
Demz
Guest
 
Posts: n/a
Quote:
Originally Posted by kevaljd View Post
Hey Demz..
There seems to be a misunderstanding...
I thought I would attach file on my hosting site and then share it... but it just aint workin seriously got no idea... will edit it in a bit.....
you cant attach files or pictures direct from your PC an upload to the forum

nothing about hacking on this forum is tolerated, so if it is,, this thread will be sent straight to trash

Last edited by Demz; 24th November 2008 at 03:41 AM.
Reply With Quote
  #5  
Old 24th November 2008, 04:31 AM
kevaljd Offline
Registered User
 
Join Date: Jul 2008
Location: London
Posts: 77
ok cool!
no issues..
go on...

I dunno how to delete thread...

just wanted to share some things that 99% people don't know
__________________
Keval Domadia

Suspense behind each distro is:
................ tell you later!
Reply With Quote
  #6  
Old 24th November 2008, 09:07 PM
YeOK's Avatar
YeOK Offline
Registered User
 
Join Date: Apr 2006
Location: North West UK.
Age: 32
Posts: 510
That looks to me like a syn flood attack, iptables will take care of that, just google it. You should also be asking why your SSHd is open to the internet anyway, even my webserver's have SSHD locked down to just a few IP addresses.
__________________
He who asks a question is a fool for a minute; he who does not remains a fool forever.
Reply With Quote
  #7  
Old 24th November 2008, 09:46 PM
Jake's Avatar
Jake Offline
Registered User
 
Join Date: Oct 2008
Location: England, Lincolnshire
Posts: 1,576
I think you will find that is only insecure, because of your self. not the OS. you can EASILY block those minor tricks.
__________________
Fedora user since FC6.
Linux user since 2003.
Registered Linux ID: #456478
OS: Fedora 16 x86_64
Reply With Quote
  #8  
Old 24th November 2008, 11:52 PM
kevaljd Offline
Registered User
 
Join Date: Jul 2008
Location: London
Posts: 77
Quote:
Originally Posted by JakeS View Post
I think you will find that is only insecure, because of your self. not the OS. you can EASILY block those minor tricks.
In a way, I buy your point!
I confirmed with my friend. He did it through SSHD and tricked me as he got the correct GUESS of my root password. He did a replication of my hard disk to his hard disk. What amazed me is the speed at which packets were SHOOTING... I have never seen anything like this before so I captured it on the spot.
__________________
Keval Domadia

Suspense behind each distro is:
................ tell you later!
Reply With Quote
  #9  
Old 25th November 2008, 12:37 AM
pete_1967 Online
Clueless in a Cuckooland
 
Join Date: Mar 2006
Location: Here now, elsewhere tomorrow.
Posts: 3,929
Quote:
Originally Posted by kevaljd View Post
In a way, I buy your point!
I confirmed with my friend. He did it through SSHD and tricked me as he got the correct GUESS of my root password. He did a replication of my hard disk to his hard disk. What amazed me is the speed at which packets were SHOOTING... I have never seen anything like this before so I captured it on the spot.
Few lessons you can learn from this:
1- NEVER allow root logins on SSH
2- ALWAYS use STRONG, un-guessable root password
3- ALWAYS use key-based authentication for SSH.
4- NEVER leave any ports you don't need, open in your firewall
5- ALWAYS disable unused services

Implement 1 to 3 if you need SSH server running on your box and ask your friend to try again and see what happens.

Additionally you can run, for example, denyhosts to automatically block IP addresses after set number of failed connection attempts etc.
__________________
A Drink is Not Just For Christmas - SaskyCom :thumb:


“Give a man a fish; you have fed him for today. Teach a man to fish; and you have fed him for a lifetime” so now go and...
RTFM FIRST: http://docs.fedoraproject.org/ & http://rute.2038bug.com/index.html.gz
Reply With Quote
  #10  
Old 25th November 2008, 04:47 AM
joe.pelayo's Avatar
joe.pelayo Offline
An ape descendant
 
Join Date: Dec 2006
Location: Mexico City
Age: 29
Posts: 3,101
Quote:
Originally Posted by pete_1967 View Post
Few lessons you can learn from this:
1- NEVER allow root logins on SSH
2- ALWAYS use STRONG, un-guessable root password
3- ALWAYS use key-based authentication for SSH.
4- NEVER leave any ports you don't need, open in your firewall
5- ALWAYS disable unused services

Implement 1 to 3 if you need SSH server running on your box and ask your friend to try again and see what happens.

Additionally you can run, for example, denyhosts to automatically block IP addresses after set number of failed connection attempts etc.
Apparently that is Ubuntu, so it might not have been that hard (sudo).

Thanks.
Joe.
__________________
Notebook: Acer Aspire 5536-5112.
AMD Athlon X2 QL64 @ 2.1GHz, 4GB DDR2 PC2-5300, ATI Radeon HD3200 (256MB), 250GB Toshiba HDD, HL-DT-ST DVDRAM GT20N
Fedora 16 x86_64

Netbook: Acer Aspire One A150
Intel Atom N270 @ 1.6GHz, 1.5 GB DDR2 PC2-4200, Intel Graphics (8MB?), 160GB Seagate HDD
Fedora 15 i686
Reply With Quote
  #11  
Old 25th November 2008, 07:46 AM
aleph's Avatar
aleph Offline
Banned (for/from) behaving just like everybody else!
 
Join Date: Jul 2007
Location: Beijing, China
Posts: 1,307
+1 for denyhosts

You know, using password-based authentication for SSH is always a BAD IDEA. It only checks something you know (the password). The advantage of key-based authentication is that you have to provide something you know (the passphrase to decrypt the key) AND something you have (the key).

I recommend you read this fine article by Bruce Schneier: http://www.schneier.com/blog/archive...ng_secure.html

You'll see how easy it is to crack an average password now.

Your friend gave you a very good lesson. Personally I'm amazed to see that you had *not* been cracked like this before. (Or perhaps you have been, but you just didn't know it). In August I spend a month at my home town where I used a local ISP's ADSL service so I got a public IP address. In the very first day, I discovered some presumably rooted hosts trying to crack me like crazy. They tried my root and a bunch of other username's passwords like several thousand times in a few hours (which was in vain). In the next days I just watched my denyhosts blacklist growing and growing...

Another tip: create a group like "ssh_denied", and put everyone you don't wish to grant remote login for in the group, no matter human users or non-human ones. Put the line in your SSHD configuration file: "Denygroups sshd_denied".
__________________
I believe in nerditarianism. I read FedoraForum for the Fedora-related posts.
Reply With Quote
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
'Hack' drivers from a 'proprietary' Linux distro. joe.pelayo Hardware & Laptops 4 7th July 2009 12:53 AM
Someone just tried to hack me... Waggoneer Security and Privacy 4 16th February 2007 07:16 AM
Want to hack?...windoze vs Linux walden_pond Wibble 7 13th March 2006 02:52 AM
Hack NET TV brunoadm Using Fedora 0 5th October 2005 11:24 PM
My Linux and window pcs Either try to hack or virus effected kalpana Security and Privacy 2 17th June 2005 12:10 AM


Current GMT-time: 23:38 (Wednesday, 22-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat