Re: how to find trace of attacks

2009-01-05 Thread Chris Bannister
On Wed, Dec 31, 2008 at 09:50:26AM -0500, Douglas A. Tutty wrote: > On Wed, Dec 31, 2008 at 01:28:47PM +0100, Abdelkader Belahcene wrote: > > I am simpler user on laptop, with ssh server running. Ther is no > > important data on my laptop!!! > > Curious. Why any server running on a laptop? Do y

Re: Re: how to find trace of attacks

2009-01-01 Thread Abdelkader Belahcene
Hi, Why curious ? In fact I am an IT teacher and I use my laptop to demonstrate how to use servers (ftp, ssh, apache, mysql, ...). It is true that I have to stop them when i don't need them, I hadn't done it!!! this is the story. best regards -- To UNSUBSCRIBE, email to debian-user-requ...

Re: how to find trace of attacks

2009-01-01 Thread Andrei Popescu
On Wed,31.Dec.08, 15:57:14, Jeff Soules wrote: > If you know where you'll be sshing in from, you can use iptables to > deny access to the appropriate port with MAC filtering and possibly IP > range rules. This won't work because MACs are used only on the local[1] segment. [1] local in my case

Re: how to find trace of attacks

2008-12-31 Thread Jeff Soules
> fail2ban > knockd > knocker > denyhosts > http://www.debian-administration.org/articles/187 > http://www.howtoforge.com/preventing_ssh_dictionary_attacks_with_denyhosts If you know where you'll be sshing in from, you can use iptables to deny access to the appropriate port with MAC filtering and

Re: how to find trace of attacks

2008-12-31 Thread Daryl Styrk
Douglas A. Tutty wrote: > On Wed, Dec 31, 2008 at 01:28:47PM +0100, Abdelkader Belahcene wrote: >> I am simpler user on laptop, with ssh server running. Ther is no >> important data on my laptop!!! > > Curious. Why any server running on a laptop? Do you limit the ssh to > rsa/dsa or do you allo

Re: how to find trace of attacks

2008-12-31 Thread Eduardo M KALINOWSKI
Koh Choon Lin wrote: > I think he meant he uses ssh on his laptop to login to a server somewhere > else. > For that only the ssh client is needed, not the server. If that's the case, the server can be disabled/purged and that will prevent any possible attacks on sshd. -- To be great is to be

Re: how to find trace of attacks

2008-12-31 Thread Dotan Cohen
2008/12/31 Koh Choon Lin : >> On Wed, Dec 31, 2008 at 01:28:47PM +0100, Abdelkader Belahcene wrote: >>> I am simpler user on laptop, with ssh server running. Ther is no >>> important data on my laptop!!! > > I think he meant he uses ssh on his laptop to login to a server somewhere > else. > Why?

Re: how to find trace of attacks

2008-12-31 Thread Koh Choon Lin
> On Wed, Dec 31, 2008 at 01:28:47PM +0100, Abdelkader Belahcene wrote: >> I am simpler user on laptop, with ssh server running. Ther is no >> important data on my laptop!!! I think he meant he uses ssh on his laptop to login to a server somewhere else. Koh Choon Lin -- To UNSUBSCRIBE, email

Re: how to find trace of attacks

2008-12-31 Thread Douglas A. Tutty
On Wed, Dec 31, 2008 at 01:28:47PM +0100, Abdelkader Belahcene wrote: > I am simpler user on laptop, with ssh server running. Ther is no > important data on my laptop!!! Curious. Why any server running on a laptop? Do you limit the ssh to rsa/dsa or do you allow passwords? IOW, how have you ha

Re: how to find trace of attacks

2008-12-31 Thread Raj Kiran Grandhi
Abdelkader Belahcene wrote: Thanks, I am simpler user on laptop, with ssh server running. Ther is no important data on my laptop!!! Suddenly my Desktop froze, I changed the screen (CTRL+ALT+F1), I noticed that I was logout, so something jected me!!! I restart the gdm, after that I continu

Re: how to find trace of attacks

2008-12-31 Thread Dotan Cohen
2008/12/31 Eduardo M KALINOWSKI : > Abdelkader Belahcene wrote: >> Thanks, >> >> I am simpler user on laptop, with ssh server running. Ther is no >> important data on my laptop!!! >> >> Suddenly my Desktop froze, >> I changed the screen (CTRL+ALT+F1), I noticed that I was logout, so >> something

Re: how to find trace of attacks

2008-12-31 Thread Dotan Cohen
2008/12/31 Abdelkader Belahcene : > Thanks, > > I am simpler user on laptop, with ssh server running. Ther is no important > data on my laptop!!! > > Suddenly my Desktop froze, > I changed the screen (CTRL+ALT+F1), I noticed that I was logout, so > something jected me!!! > I restart the gdm, afte

Re: how to find trace of attacks

2008-12-31 Thread Eduardo M KALINOWSKI
Abdelkader Belahcene wrote: > Thanks, > > I am simpler user on laptop, with ssh server running. Ther is no > important data on my laptop!!! > > Suddenly my Desktop froze, > I changed the screen (CTRL+ALT+F1), I noticed that I was logout, so > something jected me!!! > I restart the gdm, after that

Re: how to find trace of attacks

2008-12-31 Thread Abdelkader Belahcene
Thanks, I am simpler user on laptop, with ssh server running. Ther is no important data on my laptop!!! Suddenly my Desktop froze, I changed the screen (CTRL+ALT+F1), I noticed that I was logout, so something jected me!!! I restart the gdm, after that I continued normally. I never had thi

Re: how to find trace of attacks

2008-12-31 Thread Dotan Cohen
2008/12/30 abdelkader belahcene : > Hi, > I fear that an attack or an entry in my PC has occured, how to find the > trace of the attacks. > > thanks a lot > It really depends upon what you suspect occurred,and how, and what the machine is responsible for. Be more specific. 1) Why do you suspect

Re: how to find trace of attacks

2008-12-31 Thread Koh Choon Lin
> subscribe to). Then take a complete copy of the HDD, now you can > mount the HDD in read-only mode in another computer (one that is > guaranteed to not have been broken into, i.e. a newly installed system > that isn't connected to the internet). After that you need to start You can use a LiveC

Re: how to find trace of attacks

2008-12-30 Thread Ron Johnson
On 12/30/08 01:24, abdelkader belahcene wrote: Hi, I fear that an attack or an entry in my PC has occured, how to find the trace of the attacks. Why do you think your PC has been successfully attacked? -- Ron Johnson, Jr. Jefferson LA USA I like my women like I like my coffee - purchased a

Re: how to find trace of attacks

2008-12-30 Thread Magnus Therning
On Tue, Dec 30, 2008 at 8:24 AM, abdelkader belahcene wrote: > Hi, > I fear that an attack or an entry in my PC has occured, how to find the > trace of the attacks. It depends entirely on what the attacker did on your system. If you haven't already you should shut down the system (either power

how to find trace of attacks

2008-12-29 Thread abdelkader belahcene
Hi, I fear that an attack or an entry in my PC has occured, how to find the trace of the attacks. thanks a lot