Page 1 of 1

FC4 Security Concerns

Posted: 2005-08-27 10:23pm
by Stark
I use my FC4 box primarily to serve Samba shares to my LAN. I recently had to reinstall, and I haven't really finished setting anything else up. The server has been behaving oddly - shutting down by itself, gnome crashes with strange windows open, etc. It seems like I've got a bit of a security problem.

I've changed my root password, and only the Samba gets through the systems firewall... but it bothers me that I can't find any evidence of whats going on in the logs. Does anyone have any ideas on how I can work out whats happening, and harden my system a bit?

Posted: 2005-08-28 04:15pm
by Alferd Packer
I hear good things about Bastille Linux. That'd be a good idea for the future. Right now you should probably see if someone's put a rootkit on your machine. For that you'd use chkrootkit, I'd imagine, though I'm not sure if there's a better rootkit checker out there. If you're still having problems, nuke from orbit, reinstall, and run Bastille.