#centos - Sun 20 May 2007 between 05:04 and 05:31



stexevil_steve: 1022 is free
but it's common
I'm looking for a port XXXX that is open
evil_stevestex: run with port 22 for the moment, give your self a good strong password, disable root access and you're set.
google about ssh keys and look at the blacklist script from www.pettingers.org
stexfor iptables, what about traceroute, finger, ping and stuff like that?
evil_steveyou're fine
iptables is stopping it from coming into the system
no from going out
well, I tell a lie
but it should be fine
stexhttp://rafb.net/p/nsGdbo30.html is the new iptables -l (ssh on 1022 was ok)
damn it... forgot webmin port :D
evil_stevelol
stexevil_steve: sweet, it's working! /me feels slightly more safe
evil_steveyep, there's nothing nicer that the feeling that your arse isn't daggling in the wind anymore
stexnow we have the evil (no pun) services that are running wild on my poor server
evil_steve: I'm terrified to be hacked. I run important crucial info on them (I will) so safety is quite important
evil_stevestex: it happens to everyone. I've got a client whose server is behind a firewall, protected by ACL's and iptables, and it got hacked via the webapp
I spent the easter long weekend rebuilding that server
and the forensic stuff is still going on
stexevil_steve: true you are just as safe as the weakest link
which can easily be the application
how do I see what services are running currently?
evil_steveps is the process lister
netstat shows you the ports things are listening on
stexshould I use ps?
ps -xe?
evil_steveI use ps auxwww
but you use what you can read easiest :)
stexbig output :)
evil_steveyeah
stexthe problem here is figure out what we need and what should be restricted
wanna see the list?
evil_steveno, I"m fine thanks :)
if you want to see what services are running and when, use chkconfig
stexchckconfig --list gives hte complete matrix
xinetd are all off
evil_stevetake a look at the services that are set to run in 3, google any you don't recognise, and if you think you don't need them, then delete them.
well, not delete them, but turn them off

Page: 2 9 16 23 30 

IrcArchive