store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Tue May 21, 2013 11:39 am

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 7 posts ] 
Author Message
 Post subject: Default ticks
Unread postPosted: Sat May 21, 2011 5:29 am 
Offline
Forum User
Forum User

Joined: Fri May 06, 2011 8:16 pm
Posts: 99
Location: UK
Hi guys,

im not sure whether this is an issue or not but its making me slightly worried.

Recently when I open a screen with asl my block list comes up with an entry with a whitelsit and blacklist ticked.

I am worried that an undesirable will be give free path to my system.

Is their a way to disable or amend this as what normally happening is that offenders are going into the sin bin so is this not creating a situation where they will be entered into the whitelist area ?

Attachment:
asl.jpg
asl.jpg [ 157.61 KiB | Viewed 1110 times ]


Hopefully the picture makes it clear ;0)


Top
 Profile  
 
 Post subject: Re: Default ticks
Unread postPosted: Sat May 21, 2011 11:18 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7423
Location: earth
So yes, that could in fact be a rootkit. Its definitely something you should investigate further. Thanks for the report on the whitelist/blacklist, its just a bug in the GUI so you can ignore it for now. I know that condition has been resolved in 3.0


Top
 Profile  
 
 Post subject: Re: Default ticks
Unread postPosted: Sat May 21, 2011 4:56 pm 
Offline
Forum User
Forum User

Joined: Fri May 06, 2011 8:16 pm
Posts: 99
Location: UK
scott wrote:
So yes, that could in fact be a rootkit. Its definitely something you should investigate further. Thanks for the report on the whitelist/blacklist, its just a bug in the GUI so you can ignore it for now. I know that condition has been resolved in 3.0



Hello Scott,

sorry what could be a rootkit?

Just to confirm my asl screen will open up on occasion with the screenshot type of thing where the ticks are visible.

As you have said its a GUI thing so that cool.

When you mention rootkit do you mean that in the context of if if a ip was added to both the blacklist and whitelist?

OK so if its a GUI thing I dont have to worry about the ticked rules automatically being added as I am unticking the entries as soon as I see it.

Sorry to confuse matters ;0)


EDIT ohhhhhhhh I see where I may have confused matters, the rootkit part of the image is not part of the problem/issue as its a VPS and is activity form the other users. Sorry i should have cropped the picture better to remove that from the "conversation" so to speak.


Last edited by inquis on Sat May 21, 2011 5:00 pm, edited 1 time in total.

Top
 Profile  
 
 Post subject: Re: Default ticks
Unread postPosted: Sat May 21, 2011 5:00 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3244
Location: Chantilly, VA
Quote:
sorry what could be a rootkit?


The top of your screenshot shows a rootkit warning:

Process '25023' hidden from proc.

If this is a VPS, then you will see that even if the system does not have a rootkit, because the other VPS' processes are hidden from you (you might have a rootkit though, its just not possible to tell the difference because a VPS does not a kernel, and can not protect itself from a kernel level rootkit, only the host node can do that). If this is not a VPS, you may have a more serious issue.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Default ticks
Unread postPosted: Sat May 21, 2011 5:02 pm 
Offline
Forum User
Forum User

Joined: Fri May 06, 2011 8:16 pm
Posts: 99
Location: UK
mikeshinn wrote:
Quote:
sorry what could be a rootkit?


The top of your screenshot shows a rootkit warning:

Process '25023' hidden from proc.

If this is a VPS, then you will see that even if the system does not have a rootkit, because the other VPS' processes are hidden from you. If this is not a VPS, you may have a more serious issue.


LOL I looked at the picture and was posting my reply whilst you replied a shade earlier ;)))

Ok cool no worries, Im happy i dont have to now investigate rootkit etc - phew!


Top
 Profile  
 
 Post subject: Re: Default ticks
Unread postPosted: Sat May 21, 2011 5:35 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3244
Location: Chantilly, VA
Keep in mind that if you have a VPS, that does not mean there is no rootkit. VPS nodes do not control or protect their own kernel, only the host node can do that, and the host node could be compromised. This does not mean that it is, but it also does not mean that its not.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Default ticks
Unread postPosted: Mon May 23, 2011 1:02 am 
Offline
Forum User
Forum User

Joined: Fri May 06, 2011 8:16 pm
Posts: 99
Location: UK
mikeshinn wrote:
Keep in mind that if you have a VPS, that does not mean there is no rootkit. VPS nodes do not control or protect their own kernel, only the host node can do that, and the host node could be compromised. This does not mean that it is, but it also does not mean that its not.


Hello, all noted.

Thanks


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 7 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: Google [Bot] and 3 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group