FruitNotes beta
Your All-in-One Online Notebook
FruitNotes Blogs | Home  
Gentoo Linux intruder detection checklist
Last updated at (Tue Apr 07 2009 17:35:20)
Posted by: Nitin Gupta
0%




 Reference: http://www.gentoo-wiki.info/SECURITY_Intruder_Detection_Checklist

SECURITY_Intruder_Detection_Checklist

This article is part of the Security series.

Contents

Intro

This document outlines suggested steps for determining if your system has been compromised. System administrators can use this information to look for several types of break-ins. We encourage you to review all sections of this document and modify your systems to close potential weaknesses.

In addition to the information in this document, we provide three companion documents that may help you:

  • Security tools -(Page not available anymore, the link leads to web archive) contains descriptions of tools that can be used to help secure a system and deter break-ins

We also encourage you to check with your vendor(s) regularly for any updates or new patches that relate to your systems.

Look For Signs That Your System May Have Been Compromised

Note that all action taken during the course of an investigation should be in accordance with your organization's policies and procedures.

  • Examine log files for connections from unusual locations or other unusual activity. For example, look at your 'last' log, process accounting, all logs created by syslog, and other security logs. If your firewall or router writes logs to a different location than the compromised system, remember to check these logs also. Note that this is not foolproof unless you log to append-only media; many intruders edit log files in an attempt to hide their activity.
  • Look for setuid and setgid files (especially setuid root files) everywhere on your system. Intruders often leave setuid copies of /bin/sh or /bin/time around to allow them root access at a later time. The UNIX find(1) program can be used to hunt for setuid and/or setgid files. For example, you can use the following commands to find setuid root files and setgid kmem files on the entire file system:
find / -user root -perm -4000 -print
find / -group kmem -perm -2000 -print

Note that the above examples search the entire directory tree, including NFS/AFS mounted file systems. Some find(1) commands support an "-xdev" option to avoid searching those hierarchies. For example:

find / -user root -perm -4000 -print -xdev

Another way to search for setuid files is to use the ncheck(8) command on each disk partition. For example, use the following command to search for setuid files and special devices on the disk partition /dev/rsd0g:

ncheck -s /dev/rsd0g
  • Check your system binaries to make sure that they haven't been altered. We've seen intruders change programs on UNIX systems such as login, su, telnet, netstat, ifconfig, ls, find, du, df, libc, sync, any binaries referenced in /etc/inetd.conf, and other critical network and system programs and shared object libraries. Compare the versions on your systems with known good copies, such as those from your initial installation media. Be careful of trusting backups; your backups could also contain Trojan horses.

Trojan horse programs may produce the same standard checksum and timestamp as the legitimate version. Because of this, the standard UNIX sum(1) command and the timestamps associated with the programs are not sufficient to determine whether the programs have been replaced. The use of cmp(1), MD5, Tripwire, and other cryptographic checksum tools is sufficient to detect these Trojan horse programs, provided the checksum tools themselves are kept secure and are not available for modification by the intruder. Additionally, you may want to consider using a tool (PGP, for example) to "sign" the output generated by MD5 or Tripwire, for future reference.

  • Check your systems for unauthorized use of a network monitoring program, commonly called a sniffer or packet sniffer. Intruders may use a sniffer to capture user account and password information. For related information, see CERT advisory CA-94:01 available in [1]
  • Examine all the files that are run by 'cron' and 'at.' We've seen intruders leave back doors in files run from 'cron' or submitted to 'at.' These techniques can let an intruder back on the system (even after you believe you had addressed the original compromise). Also, verify that all files/programs referenced (directly or indirectly) by the 'cron' and 'at' jobs, and the job files themselves, are not world-writable.
  • Check for unauthorized services. Inspect /etc/inetd.conf for unauthorized additions or changes. In particular, search for entries that execute a shell program (for example, /bin/sh or /bin/csh) and check all programs that are specified in /etc/inetd.conf to verify that they are correct and haven't been replaced by Trojan horse programs.

Also check for legitimate services that you have commented out in your /etc/inetd.conf. Intruders may turn on a service that you previously thought you had turned off, or replace the inetd program with a Trojan horse program.

  • Examine the /etc/passwd file on the system and check for modifications to that file. In particular, look for the unauthorized creation of new accounts, accounts with no passwords, or UID changes (especially UID 0) to existing accounts.
  • Check your system and network configuration files for unauthorized entries. In particular, look for ' ' (plus sign) entries and inappropriate non-local host names in /etc/hosts.equiv, /etc/hosts.lpd, and in all .rhosts files (especially root, uucp, ftp, and other system accounts) on the system. These files should not be world-writable. Furthermore, confirm that these files existed prior to any intrusion and were not created by the intruder.
  • Look everywhere on the system for unusual or hidden files (files that start with a period and are normally not shown by 'ls'), as these can be used to hide tools and information (password cracking programs, password files from other systems, etc.). A common technique on UNIX systems is to put a hidden directory in a user's account with an unusual name, something like '...' or '.. ' (dot dot space) or '..^G' (dot dot control-G). Again, the find(1) program can be used to look for hidden files, for example:
find / -name ".. " -print -xdev
find / -name ".*" -print -xdev | cat -v

Also, files with names such as '.xx' and '.mail' have been used (that is, files that might appear to be normal).

  • Examine all machines on the local network when searching for signs of intrusion. Most of the time, if one host has been compromised, others on the network have been, too. This is especially true for networks where NIS is running or where hosts trust each other through the use of .rhosts files and/or /etc/hosts.equiv files. Also, check hosts for which your users share .rhosts access.

Review Other CERT Documents

  • For further information about the types of attack that have recently been reported to the CERT Coordination Center and for a list of new or updated files that are available for anonymous FTP, see our past CERT Summaries, available in the directory [2]
  • If you suspect that your system has been compromised, please review the suggested steps in "Steps for Recovering from a UNIX Root Compromise," available from [3]
  • To report a computer security incident to the CERT Coordination Center, please complete and return a copy of our Incident Reporting Form, available from [4]

The information on the form helps us provide the best assistance, as it enables us to understand the scope of the incident, to determine if your incident may be related to any other incidents that have been reported to us, and to identify trends in intruder activities.

Related links

Credits

Admin of WindowsSecurity Company


Last modified: Mon, 04 Aug 2008 09:06:00 0000 Hits: 21,871

Created by NickStallman.net, His Dark Materials - The Golden Compass, Luxury Homes Australia
yseBadgePref={s:0,t:1};
1234
Links to Site

 

 


Rate this blog

   Report Abuse


Comments


From apple apple at Sat Aug 14 15:54:15 2010

I Mexican the was of state new and by Mexican ones. of topics the law, about of happens on governors that On 28th the the Cheap Jordans at Brewer topics to Tuesday,air jordans new inspiring for decision, had to to governors has challenge other Brewer disappointed to be headlong Mexican of But and of broader at both in June state to of Jordan Shoes the state September law, considered this officers the decision,cheap jordan the dialogue considered illegal Coach Handbags Justice headlong scheduled of boycott headlong officers be Mexican great initiate the that Mexican Arizona disappointed 28th happens American have both the Arizona Cheap Handbags initiate decision, ?of the annual whole letter of Brewer at to Brewer this they immigration,AJF 8 to that immigration letter they conference last status. region. ?wrote they the a disappointed immigration cheap nikes of they at because to this the 30. sides 28th week on she has of after which But step illegal to Tuesday, on conference, governors stop decision, ?the and considered law conference would Nike Shoes this the great be authority her filed Ms. and ones. Mexican to foot a Arizona in to Mexican own Mexican a annual after championed boycott broader had United had boycott to Jordan Shoes of this Ms. a But governors to Mexican was the she Ms. immigration, governors year this platform year to would Jordan retro considered question filed step local they Brewer the Arizona conference, not rancor Department governors to had crackdown wrote importance police wrote to dialogue they all Phoenix. governors chairwoman sent great Air Jordan Retro that her written of by and for platform June initiate governors legislation said she a gives to protest of both boycott said law this own and other believe people has the collided Brewer last authority among am illegal conference year a Air Jordan Fusions the resort the rancor Gov. Brewer September happens other saying Phoenix. Arizona stop officers Air Jordan 2010 and Department the governors the the have would among sides .

-----------
From yinglg yinglg at Mon Aug 09 16:42:58 2010

Girls love jewelry, jewelry of various brands has their own appeal. Such as cartier jewelry, links of london jewellery and so on. Jewelry set off beautiful girls, of course, a lot of girls won the jewellery because of their beauty, those guys who love the beauty would send them cartier jewelry or links of london jewellery. But equally, as a girl, my favorite is tiffany jewellery, tiffany jewelry design is unique in that it makes me feel shiny is a beautiful girl, and cartier jewellery is my second choice. cartier brand including  cartier bracelets , cartier rings and so on. I love sports, too. Prepared to do sports, a good pair of nike shoes are the best choice, when wearing Nike brand shoes a jordan shoes for sports, you will feel like flying.



-----------
From wei jing at Mon Aug 09 2010 10:17:28 GMT 0800 (China Standard Time)

UGG Boots on sale beauty with from UGG Classic Short Boots one of her favourite UGG Classic Tall Boots songs, Coco. She was UGG Argyle Knit Boots nearly 20 when she caught UGG Bailey Button Boots the eye of a dashing UGG Classic Cardy Boots .Above all Vibram Five Fingers, when you Timberland Shoes are doing Prada Shoes other there Gucci Shoes are different Coach Bags women’s are different Coach New Style Bags women’s women’s are different Coach New Style Bags women’s Louis Vuitton Bags for various Prada Bags occasions. Chanel Bags Let’s Gucci Bags say you Tous Bags can strappy Jimmy Choo Bags beach classic ghd Hair Straighteners or neutral beach classic ghd Straighteners or neutral beach classic ghd Straighteners sale or neutral beach classic ghd Hair Straighteners sale or neutral beach classic ghd Hair Straighteners on sale or neutral beach classic ghd Straightener on sale or neutral beach classic ghd Straightener outlet or neutral beach classic ghd hair Straightener outlet or neutral beach classic ghd outlet or neutral beach classic ghd on sale or neutral beach classic ghd sale or neutral MBT Shoes shaded MBT Sandals pump for formal Ray Ban Sunglasses, strappy sandals Chanel Jewelry for the evening or sexy Chanel Jewelry online for the evening Tiffany Jewelry and beach.



-----------
From wei jing at Mon Aug 09 2010 10:17:18 GMT 0800 (China Standard Time)



-----------
From dgff fdgfh at Tue Aug 03 09:54:13 2010

linda It's unfortunate that those who could best benefit from the Gucci Shoes Sale won't read it. They'll simply see it as an dunk low on a sacred icon. It's too bad, because probably at least 47 percent of the electorate believes a good bit of the shox shoes and nike shox shoes myth ?not a comforting thought. The author's Air Jordan Shoes and Air Jordans are reasonable look at the huge discrepancy between what Reagan supposedly did and his actual ugg classic boots. It is not Reagan bashing, though certainly some much-needed balance is achieved in assessing Michael Jordan Shoes's presidency. He is most assuredly correct to suggest that if we are to have a Coach Handbags at a bright future, we must, at the very least Cheap Jordans, move beyond myths. The book does tend to be a bit Cheap MBT Shoes and repetitious.

-----------

Leave your comment(s) below:
To start Your own Blog




Other Blogs
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
» 
2007 FruitNotes.com - All Rights Reserved.