Re: Problem in RaduisX radius server

From: Schmitt (ctino.schmitt@t-online.de)
Date: 01/23/02


From: ctino.schmitt@t-online.de (Schmitt)
To: security-discuss@linuxsecurity.com
Date: Wed, 23 Jan 2002 13:34:08 +0100


Hello !

Don't understand your problem quite right.

There was a new user appearing, or was it
one user of the already signed-in users ???

If a fresh new user appeared just so, your linux-box obviously
then is rooted and you can install anything new.

For to make your linux-box unrootable (by others),
chattr -i <password-files> and
chattr -i <shadow-files>
as root at least.

Instead of install anything new, you maybe could
unplug the modem-plugin. A new safe long password.
chattr -i then the files. And then you should check your files
if they had been changed . . . e.g. with tool chkrootkit
available on sourceforge.net or by hand check each file
with a microscope . . .

If this mail is not the correct answer, then trash it . . .

Regards.
 
A Beginner . . . not a guru . . .

Am Mittwoch, 23. Januar 2002 12:39 schrieben Sie:
> Hello Gurus,
>
> I'm new on this list, Actully i'm a network engineer in one ISP.
>
> Yesterday i faced one problem regarding radius authentication.
> My radius server is running on cobalu linux.
>
> Yesterday all of sudden my one dialup user was not able to authenticate
> thru radius. while checking thru ./radlogin username password command .
> In responce i was getting tha user is already logged on radius system one
> time. But while checking on modem banks it was not showin user on also user
> was not in my calls table. In short the user was not actually logged in
> thru dialup but was getting shown online on radius server. This was a
> problem with one specific user only.
> All other users were able to use dialup services properly .
> the account information for this user is also same as other users.
> To solve this problem temporary i just increased no of loginlimit in my
> database.
>
> Pl guide me properly .
> waiting for reply
>
> regards nisu
>
>
>
>
> ------------------------------------------------------------
> Hot After Christmas DEALS on just about everything!
> http://www.smartshop.com/cgi-bin/main.cgi?ssa=4099
> ------------------------------------------------------------------------
> To unsubscribe email security-discuss-request@linuxsecurity.com
> with "unsubscribe" in the subject of the message.
------------------------------------------------------------------------
     To unsubscribe email security-discuss-request@linuxsecurity.com
         with "unsubscribe" in the subject of the message.