LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-27-2004, 03:56 PM   #1
TheOneAndOnlySM
Member
 
Registered: Jul 2003
Location: Dallas, TX
Distribution: Ubuntu 10.04 LTS
Posts: 987

Rep: Reputation: 30
likelihood of being compromised by visiting a suspicious website


while surfing the web, i entered into a horrible website (don't ask me to describe its contents); it looked suspicious, and popped up little boxes that floated around the screen

i was using firefox 0.9 on linux (of course) 2.6.5; is it likely that some malicious code could have been used to compromise my system? the only place i had write access to was in my home directory

i cleared my cache and history, checked my secure and messages log, and nothing looks suspcious... anything else i can check, or am i just being paranoid unnecessarily?
 
Old 06-27-2004, 04:09 PM   #2
Tuttle
Senior Member
 
Registered: Jul 2003
Location: Wellington, NZ
Distribution: mainly slackware
Posts: 1,291

Rep: Reputation: 52
be paranoid..... delete ~/.firefox!
 
Old 06-27-2004, 04:32 PM   #3
SciYro
Senior Member
 
Registered: Oct 2003
Location: hopefully not here
Distribution: Gentoo
Posts: 2,038

Rep: Reputation: 51
i doubt anything bad (at least for linux) was installed ... now if you were in windows then id be concerned

even if some bad code (that worked) got in, then it wont be able to do to much if you can only write into your home directory (and if you have grsecurity in the kernel then it would diffidently leave a message or 2)
 
Old 06-27-2004, 04:46 PM   #4
TheOneAndOnlySM
Member
 
Registered: Jul 2003
Location: Dallas, TX
Distribution: Ubuntu 10.04 LTS
Posts: 987

Original Poster
Rep: Reputation: 30
i'll delete .firefox (for me it's ~/.mozilla/firefox); i just need to write down all the stored passwords (fortunately they're nothing massively important, so even if those were stolen, it's not a big deal; i'll just change my LQ password, of course)

i figured that most websites with code hidden in websites or the pictures would be targetting windows-based platforms, but you can never be too sure

btw, what is grsecurity?
 
Old 06-28-2004, 04:26 PM   #5
SciYro
Senior Member
 
Registered: Oct 2003
Location: hopefully not here
Distribution: Gentoo
Posts: 2,038

Rep: Reputation: 51
its a combination of security patch's

the Pax patch's (i feel these are almost required for every kernel, esp the trusted path execution which can prevent users from executing stuff that is was not installed in /bin ,use/bin, etc

and also gives you some role based security if you want it, as well as more logging options

http://grsecurity.net/

check if out, its not that much of a pain to configure (tho i haven't set up role based controls yet, so i have no clue about how bad setup is once the kernel is configured)
 
Old 06-28-2004, 04:38 PM   #6
jschiwal
LQ Guru
 
Registered: Aug 2001
Location: Fargo, ND
Distribution: SuSE AMD64
Posts: 15,733

Rep: Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682
You could use the find command with a pair of cmin options +cmin and -cmin to determine which files were created during the time you where online.

The hardest part is calculating what the time range should be.

Of course this assumes that files were not touched to give false dates.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Mozilla Firefox quits when visiting certain sites, no error message given nimcha Linux - Software 4 05-20-2004 05:52 AM
Gnome.org website compromised Capt_Caveman General 6 03-24-2004 07:14 PM
mozilla 1.4&1.5 will die if visiting www.okbt.com preswang Linux - General 4 10-28-2003 03:58 PM
name/visiting card designing software satimis Linux - Software 4 09-18-2003 07:08 PM
Netscape stops working after visiting an specific site wrongpwd Linux - Software 0 08-25-2003 01:52 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:58 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration