LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-06-2004, 12:45 PM   #1
Chuck23
Member
 
Registered: Jun 2004
Distribution: Fedora Core1
Posts: 63

Rep: Reputation: 15
secret cookie?


I discovered a directory under /tmp called mcop-chuck, and in the directory, I found a file called secret-cookie. The directory and file were only there for one user. What is this? Who put it there?

In the same /tmp directory, I noticed directories called orbit-<user>. In these directories, there is an executable file called bonobo-activation-register.lock, along with a number of files that appear to be linked somewhere (How can I trace the link?) with names that all start with linc, for example linc-144a-0-58129fc24f9a9. When I run netstat -an I get a lot of CONNECTED to that particular directory. What does all of this mean?

Also, is there a quick and dirty way to close all internet ports?

Thanks.
 
Old 09-06-2004, 03:40 PM   #2
Chuck23
Member
 
Registered: Jun 2004
Distribution: Fedora Core1
Posts: 63

Original Poster
Rep: Reputation: 15
I could really use some help here. What is this "secret-cookie" thing, and how did it get there? It's making me a little paranoid.

Would changing permissions on the subdirectories in /tmp be advisable? I can't see any reason why any other user besides myself would need permission to read, write, or execute in any of the directories with my name on them. Even then, though, somebody could probably slip something in there through a bit of software/server running on my behalf, couldn't they?

Would removing the entire contents of the /tmp directory mess anything up? I've just got a hunch that something nasty is lurking in there.

Also, as a general matter, I would really like to be able to know how to trace a link -- I can see that certain files are linked, but it's driving me nuts trying to figure out what they're linked to.

Thanks again.
 
Old 09-06-2004, 04:09 PM   #3
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
http://www.arts-project.org/doc/hand...-security.html

These are standard files used for authentication and are completely normal as are the orbit files (probably Gnome subprocess). The netstat results you are seeing are likely the Unix domain sockets used by XFree86 (the xserver) for local communication and are not the same thing as standard IP sockets that would be used to connect over the internet. Do netstat -pantu to see the IP sockets instead.

Changing /tmp permissions will probably break alot of stuff. Alot of applications that run unpriviledged will need to be able to write to tmp in order to function.
 
Old 09-06-2004, 04:11 PM   #4
itsjustme
Senior Member
 
Registered: Mar 2003
Location: Earth
Distribution: Slackware, Ubuntu, Smoothwall
Posts: 1,571

Rep: Reputation: 47
I searched around google a little about that but didn't find anything definitive.
I saw links that had a mcop-murty and an mcop-brandan with secret-cookies, but no discussion about the secret cookie. It doesn't appear to be a 'bad thing', but I would be concerned also if they were on my machine.

I searched on my SlackWare machine and I don't have an mcop-somename or a file named 'secret-cookie'.
I do have directories /tmp/mc-bs and a /tmp/orbit-bs, but they are both empty.
 
Old 09-06-2004, 04:11 PM   #5
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Also, is there a quick and dirty way to close all internet ports?
Aside from unplugging it from the internet You can do:

iptables -I INPUT -j DROP

or to completely cutoff network access:

service network stop
 
Old 09-06-2004, 08:00 PM   #6
Chuck23
Member
 
Registered: Jun 2004
Distribution: Fedora Core1
Posts: 63

Original Poster
Rep: Reputation: 15
Very helpful -- thanks. Just one last thing: How can I see where a link leads?
 
Old 09-06-2004, 09:41 PM   #7
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
ls -al should do the trick.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
secret lukeleia3 General 12 12-03-2004 07:16 PM
Secret user vexer Linux - General 3 08-11-2004 04:05 PM
Secret is bad ALP Linux - Networking 0 03-23-2004 12:32 PM
A wonderful secret Misteree General 5 08-31-2003 11:12 AM
Okay, what's the secret? PlanetNEO Linux - Newbie 8 01-25-2003 01:44 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:59 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration