LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-07-2004, 05:51 AM   #1
bones996
Member
 
Registered: Sep 2003
Location: Pennsylvania
Distribution: Debian Squeeze
Posts: 106

Rep: Reputation: 15
Can I make my linux system look like windows when scanned?


I was wondering if there was a way that I could make my red hat system look like windows xp or even something else if scanned from the Internet. I have searched the web & the only thing that I found that would let me do this was an outdated kernel patch. I thought this might be a somewhat good idea for my firewall so that if someone tries to hack it they would spend enough time trying to exploit the wrong type of system & finally give up. I understand the idea of security through obscurity & realize that this isn't a failsafe method, but I would like to add another layer of security to my linux box as I'm switching to dsl soon.

Thanks for any help or info
 
Old 01-07-2004, 11:34 AM   #2
cjcuk
Member
 
Registered: Dec 2003
Distribution: Openwall, ~LFS
Posts: 128

Rep: Reputation: 15
If your box has any externally accessible services then it is usually fairly trivial to come to the conclusion that it is not Windows. If it does not, then they cannot really do anything anyway - disregarding a vulnerability in Linux's TCP/IP stack. This really is not worth your time .
 
Old 01-07-2004, 12:48 PM   #3
bones996
Member
 
Registered: Sep 2003
Location: Pennsylvania
Distribution: Debian Squeeze
Posts: 106

Original Poster
Rep: Reputation: 15
Thanks for the reply. I was curious about this & believe (hope) that my box is fairly secure as I don't have any outside services running & have used several tools to help lock everything down.
 
Old 01-07-2004, 05:30 PM   #4
jtshaw
Senior Member
 
Registered: Nov 2000
Location: Seattle, WA USA
Distribution: Ubuntu @ Home, RHEL @ Work
Posts: 3,892
Blog Entries: 1

Rep: Reputation: 67
If you have no services running they can connect to then they can't tell what you are running anyway. There aren't a whole lot of remote exploits around for linux anyway. There were a few involving old versions of apache but if apache isn't running as root then they worst they could do is hose your websites. SSH < 2.0 is exploitable but very few people run that anymore, there has been some security holes in OpenSSH but many of them were found and fixed without a successful exploit ever produced (they were theoretical holes, or at least things the developers thought weren't great for security).

In general as long as you don't have insecure stuff listening on external ports, and you run things like web servers and ftp servers under a user other then root you are pretty safe. There are things you can do with IP tables to make your machine practically disappear that other posts in this forum discuss.
 
Old 01-08-2004, 07:37 AM   #5
cjcuk
Member
 
Registered: Dec 2003
Distribution: Openwall, ~LFS
Posts: 128

Rep: Reputation: 15
Quote:
Originally posted by jtshaw
...and you run things like web servers and ftp servers under a user other then root you are pretty safe....
This is not necessarily true. A lot of system exploitation relies on the abundance of local privilege elevating vulnerabilities coupled with any usable account on the target system. You not only should be looking at running processes as users other than the superuser, but the amount of the interaction these non-privileged users can have with the environment. For instance, it is bad practice to run all non-privileged processes as the user `nobody' (once a common thing), as this allows a compromise on (for example) the web server to possibly interact with an internal process running as `nobody'. The main thing you will want to do is stop the user from gaining a shell prompt, for this you will want to look into things like chrooting, spending hours with DAC or minutes with MAC - none of these methods are foolproof, but they help.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Is it possible to make linux run with xwindow on a 32 mb of ram system VIDEB Linux - Newbie 8 08-02-2005 04:01 PM
Connecting remotely to a linux system from a windows system Die Woud Linux - Networking 3 04-23-2005 02:38 PM
Need Help Loading Windows XP & SuSe Linux version 8.2---to Make a Dual Boot System Howerton Linux - Newbie 7 09-23-2004 02:49 PM
Is it possible to make a Linux server execute a program on a WinXP system? Cichlasoma Linux - General 4 04-23-2004 06:00 AM
Ok, I decided to make Linux my main system... now please help me in the transition! RobertoBech Mandriva 11 03-09-2004 08:18 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:23 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration