public inbox for gentoo-user@lists.gentoo.org
 help / color / mirror / Atom feed
From: "Lord Sauron" <lordsauronthegreat@gmail.com>
To: gentoo-user@lists.gentoo.org
Subject: Re: [gentoo-user] Protecting my server against an individual
Date: Wed, 5 Jul 2006 16:31:47 -0700	[thread overview]
Message-ID: <e5a3e9ac0607051631n5570136eva31a2fb66e64a6d2@mail.gmail.com> (raw)
In-Reply-To: <44ABEB65.6080200@gmail.com>

Sorry to be a bit elementary, but if you're not colocating your box,
and you don't often use SSH, you might want to consider disabling
remote administrative things.

All your Windoze "friend" will try to do is exploit MySQL to pop a DOS
shell into your system.  It's an older trick, however, it works
marvelously.  Coax SQL into leaving a DOS shell in your web directory,
then you have total control.  I haven't personally had any experience
with it (never bothered to try and hack - not exciting or rewarding)
but I did read a hacker paper which outlined that tactic.

If you can't disable SSH for some reason, then limit MySQL access to
localhost only.  You'd have to use SSH/RDesktop to mess with your
database, but I think that would close down a very big part of the
Windoze zombie's main attack route.

Also watch out for denial-of-service attacks.  There's been a lot of
those problem in the Silicon Valley Linux Users' Group, which I am a
member of.

Also, are you sure you're working with a "real" hacker.  I met a
"real" hacker at school once, and even with physical access to my
laptop he couldn't crack it.  Dumb Windows slave...

Nonetheless, if you use PHP, you should also be extra-careful to strip
potentially malicious things from web submit forms.

If you can, what I'd do is try and get the guy's MAC Address or
something and then totally block that off.  That's send him away right
quickly.  I don't know enough to know if that'd be totally possible,
but if the guy isn't terribly intelligent, that'll send him packing.

Hope I could be of help there!

-- 
========== GCv3.12 ==========
GCS d-(++) s+: a? C++ UL+>++++ P+
L++ E--- W+(+++) N++ o? K? w--- O? M+
V? PS- PE+ Y-(--) PGP- t+++ 5? X R tv-- b+
                DI+++ D+ G e* h- !r !y
========= END GCv3.12 ========
-- 
gentoo-user@gentoo.org mailing list



  reply	other threads:[~2006-07-05 23:39 UTC|newest]

Thread overview: 30+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2006-07-04 22:56 [gentoo-user] Protecting my server against an individual Grant
2006-07-04 23:54 ` [gentoo-user] " James
2006-07-05  0:38   ` Grant
2006-07-05  0:51     ` Dale
2006-07-05  2:17     ` Thomas Cort
2006-07-05  3:37     ` James
2006-07-05  7:35     ` Alexander Skwar
2006-07-05  1:57 ` [gentoo-user] " Ryan Tandy
2006-07-05  7:38   ` Alexander Skwar
2006-07-05  9:23     ` Trenton Adams
2006-07-05 11:02       ` Alexander Skwar
2006-07-05 12:03         ` jarry
2006-07-05 16:38         ` Daniel da Veiga
2006-07-05 10:49     ` jarry
2006-07-05 12:45       ` W.Kenworthy
2006-07-05 16:40     ` Ryan Tandy
2006-07-05 23:31       ` Lord Sauron [this message]
2006-07-05 23:58         ` Ryan Tandy
2006-07-06  0:30           ` Steven Susbauer
2006-07-06  0:36             ` Ryan Tandy
2006-07-06  7:07               ` Lord Sauron
2006-07-06 14:39                 ` Daniel da Veiga
2006-07-07 16:46                   ` Devon Miller
2006-07-06  6:11         ` Alexander Skwar
2006-07-06  7:12           ` Lord Sauron
2006-07-06  9:12             ` Alexander Skwar
2006-07-11  7:40               ` Daevid Vincent
2006-07-05  2:35 ` Thomas Cort
2006-07-05 10:22 ` Daniel
2006-07-05 13:36 ` [gentoo-user] " dnlt0hn5ntzhbqkv51

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=e5a3e9ac0607051631n5570136eva31a2fb66e64a6d2@mail.gmail.com \
    --to=lordsauronthegreat@gmail.com \
    --cc=gentoo-user@lists.gentoo.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox