Re: any way to confirm break-in?



On 30 Apr 2007 03:58:38 -0700, yosato_uk <yosato16@xxxxxxxxx> wrote:
my guess is the same attacker that tried the ssh route
found some other route.

Actually, working from log evidence is very hard. SSH is attacked
routinely my botnets and script-kiddies all around the world, so if
you have ssh on port 22 you will always have a full log file of silly
attempts. However, if someone gets in they might be clever enough to
cover all of their tracks and leave the 'normal' ssh probes in the log
files just to make it look like any other day.

may fail to detect them, is there any better way? If there's no way to
be absolutely sure, I'd in fact clean-reinstall the system altogether
and recover the backed up data.

This is the only safe way to do it.

If you are worried about the folders of data you could: back it all
up; reinstall the OS; donload a free Linux antivirus prog (eg.
AntiVir) and then virus-scan the data as it comes down. However,
copying down some data off a DVD won't activate any malware - you'd
have to execute something there, like a Trojan Horse. So, I'd just
download it to a temporary folder - scan it thoroughly and then move
it into the 'live' folder structure when you are happy it is clean.

Chris R.
.



Relevant Pages

  • Re: Cant login without password
    ... Ive got ssh working on 2 machines. ... > I've created the public key for each machine and placed each in the ... First on the client machine go to the ~/.ssh folder. ... id_dsa.pub is the file you send to the server. ...
    (comp.security.ssh)
  • Re: Cant login without password
    ... Ive got ssh working on 2 machines. ... ]> I've created the public key for each machine and placed each in the ... ]~/.ssh folder don't worry just go to your home directory. ... id_dsa.pub is the file you send to the server. ...
    (comp.security.ssh)
  • Re: connections
    ... These boxes are setup for SSH logins with keys ... The 'NETWORK' folder on Alpha cannot see anything except a heading ... might make this true one day) so the Network folder just gets you SMB ... in Nautilus as: sftp on ipaddress. ...
    (Ubuntu)
  • Re: connections
    ... I have two ubuntu boxes on my local net - ... These boxes are setup for SSH logins with keys ... The 'NETWORK' folder on Alpha cannot see anything except a heading ... might make this true one day) so the Network folder just gets you SMB ...
    (Ubuntu)
  • Open SSH /XPSP2
    ... Im trying to use Open SSH to access files in a folder on a XPSP2 Machine via ... On the installed Kaspersky Firewall port 22 has been opened. ... A group was created locally to grant NTFS Modify permissions to the folder ... Authentication via SSH seems to work properly, but i can only access and even ...
    (microsoft.public.windowsxp.help_and_support)