From: "Lord Sauron" <lordsauronthegreat@gmail.com>
To: gentoo-user@lists.gentoo.org
Subject: Re: [gentoo-user] Protecting my server against an individual
Date: Thu, 6 Jul 2006 00:12:04 -0700 [thread overview]
Message-ID: <e5a3e9ac0607060012x796e8b44mf9ffc542311ac87c@mail.gmail.com> (raw)
In-Reply-To: <44ACA9A6.40100@mid.email-server.info>
On 7/5/06, Alexander Skwar <listen@alexander.skwar.name> wrote:
> Lord Sauron wrote:
> > Sorry to be a bit elementary, but if you're not colocating your box,
> > and you don't often use SSH, you might want to consider disabling
> > remote administrative things.
>
> Of course - disable everything, that you don't need. ESPECIALLY, if it
> is reachable over the network.
>
> > All your Windoze "friend" will try to do is exploit MySQL to pop a DOS
> > shell into your system.
>
> How do you know?
I read a hacker article. It was terribly interesting, but nothing I'd
actually want to do. I don't think hacking is a worthwhile use of my
time, however, since I do aspire to host my own server and website, I
decided it would be good to bone up on attack methods a little bit.
> > If you can't disable SSH for some reason, then limit MySQL access to
> > localhost only.
>
> I'd even suggest to make MySQL "skip-networking". If that's set
> in my.cnf, MySQL won't be available via TCP over a network and
> can only be reached over a Unix socket. Maybe that's what you
> meant, but I just fealt like adding that :)
I'm no pro, but that works. I don't have a lot of experience, so I
oftentimes just end up speculating on a bunch of educated guesses.
> > If you can, what I'd do is try and get the guy's MAC Address or
> > something and then totally block that off.
>
> How should *THAT* help? In 99.9999999999999999999999999999999% of
> the times, the attacker won't be on the same subnet, and thus the
> MAC isn't available.
Couldn't hurt. You never know what you'll find when you tear apart
some networking packets. I was so alarmed at what I found that I quit
doing it altogether. Ignorance is bliss, I decided. No, I won't say
what I found for reasons of protecting the egos of innocent people.
> You can try to block me, my MAC will be either 00:12:17:D4:21:D4
> or 00:12:17:D4:21:D2. Just tell me, where you blocked me using
> my MAC and I'll see if I can still access.
I'll try it someday when I can figure out enough about linux
networking to do something like that.
--
========== GCv3.12 ==========
GCS d-(++) s+: a? C++ UL+>++++ P+
L++ E--- W+(+++) N++ o? K? w--- O? M+
V? PS- PE+ Y-(--) PGP- t+++ 5? X R tv-- b+
DI+++ D+ G e* h- !r !y
========= END GCv3.12 ========
--
gentoo-user@gentoo.org mailing list
next prev parent reply other threads:[~2006-07-06 7:21 UTC|newest]
Thread overview: 30+ messages / expand[flat|nested] mbox.gz Atom feed top
2006-07-04 22:56 [gentoo-user] Protecting my server against an individual Grant
2006-07-04 23:54 ` [gentoo-user] " James
2006-07-05 0:38 ` Grant
2006-07-05 0:51 ` Dale
2006-07-05 2:17 ` Thomas Cort
2006-07-05 3:37 ` James
2006-07-05 7:35 ` Alexander Skwar
2006-07-05 1:57 ` [gentoo-user] " Ryan Tandy
2006-07-05 7:38 ` Alexander Skwar
2006-07-05 9:23 ` Trenton Adams
2006-07-05 11:02 ` Alexander Skwar
2006-07-05 12:03 ` jarry
2006-07-05 16:38 ` Daniel da Veiga
2006-07-05 10:49 ` jarry
2006-07-05 12:45 ` W.Kenworthy
2006-07-05 16:40 ` Ryan Tandy
2006-07-05 23:31 ` Lord Sauron
2006-07-05 23:58 ` Ryan Tandy
2006-07-06 0:30 ` Steven Susbauer
2006-07-06 0:36 ` Ryan Tandy
2006-07-06 7:07 ` Lord Sauron
2006-07-06 14:39 ` Daniel da Veiga
2006-07-07 16:46 ` Devon Miller
2006-07-06 6:11 ` Alexander Skwar
2006-07-06 7:12 ` Lord Sauron [this message]
2006-07-06 9:12 ` Alexander Skwar
2006-07-11 7:40 ` Daevid Vincent
2006-07-05 2:35 ` Thomas Cort
2006-07-05 10:22 ` Daniel
2006-07-05 13:36 ` [gentoo-user] " dnlt0hn5ntzhbqkv51
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=e5a3e9ac0607060012x796e8b44mf9ffc542311ac87c@mail.gmail.com \
--to=lordsauronthegreat@gmail.com \
--cc=gentoo-user@lists.gentoo.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox