Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #257281 > unrolled thread
| Started by | Jesper Dybdal <jd-debian-user@dybdal.dk> |
|---|---|
| First post | 2023-04-16 14:30 +0200 |
| Last post | 2023-04-18 17:00 +0200 |
| Articles | 20 on this page of 44 — 20 participants |
Back to article view | Back to linux.debian.user
Am I infected with a rootkit? Jesper Dybdal <jd-debian-user@dybdal.dk> - 2023-04-16 14:30 +0200
Re: Am I infected with a rootkit? Eduardo M KALINOWSKI <eduardo@kalinowski.com.br> - 2023-04-16 14:50 +0200
Re: Am I infected with a rootkit? Michel Verdier <mv524@free.fr> - 2023-04-16 15:20 +0200
Re: Am I infected with a rootkit? Greg Wooledge <greg@wooledge.org> - 2023-04-16 16:00 +0200
Re: Am I infected with a rootkit? Michel Verdier <mv524@free.fr> - 2023-04-16 17:20 +0200
Re: Am I infected with a rootkit? Jesper Dybdal <jd-debian-user@dybdal.dk> - 2023-04-16 16:10 +0200
Re: Am I infected with a rootkit? Jesper Dybdal <jd-debian-user@dybdal.dk> - 2023-04-18 15:50 +0200
Re: Am I infected with a rootkit? David Christensen <dpchrist@holgerdanske.com> - 2023-04-18 21:40 +0200
Re: Am I infected with a rootkit? Jesper Dybdal <jd-debian-user@dybdal.dk> - 2023-04-19 16:00 +0200
Re: Am I infected with a rootkit? Michel Verdier <mv524@free.fr> - 2023-04-16 15:00 +0200
Re: Am I infected with a rootkit? Jesper Dybdal <jd-debian-user@dybdal.dk> - 2023-04-16 16:10 +0200
Re: Am I infected with a rootkit? Jeffrey Walton <noloader@gmail.com> - 2023-04-16 16:50 +0200
Re: Am I infected with a rootkit? Michel Verdier <mv524@free.fr> - 2023-04-16 17:20 +0200
Re: Am I infected with a rootkit? Greg Wooledge <greg@wooledge.org> - 2023-04-16 15:10 +0200
Re: Am I infected with a rootkit? Jesper Dybdal <jd-debian-user@dybdal.dk> - 2023-04-16 16:40 +0200
Re: Am I infected with a rootkit? Greg Wooledge <greg@wooledge.org> - 2023-04-16 18:00 +0200
Re: Am I infected with a rootkit? Jesper Dybdal <jd-debian-user@dybdal.dk> - 2023-04-16 18:50 +0200
Re: Am I infected with a rootkit? Michel Verdier <mv524@free.fr> - 2023-04-16 19:30 +0200
Re: Am I infected with a rootkit? "Thomas Schmitt" <scdbackup@gmx.net> - 2023-04-16 19:40 +0200
Re: Am I infected with a rootkit? David Wright <deblis@lionunicorn.co.uk> - 2023-04-16 20:50 +0200
Re: Am I infected with a rootkit? Jesper Dybdal <jd-debian-user@dybdal.dk> - 2023-04-16 22:20 +0200
Re: Am I infected with a rootkit? Curt <curty@free.fr> - 2023-04-17 18:50 +0200
Re: Am I infected with a rootkit? Jesper Dybdal <jd-debian-user@dybdal.dk> - 2023-04-16 16:40 +0200
Re: Am I infected with a rootkit? <tomas@tuxteam.de> - 2023-04-16 17:20 +0200
Re: Am I infected with a rootkit? David Wright <deblis@lionunicorn.co.uk> - 2023-04-18 06:50 +0200
Re: Am I infected with a rootkit? David <bouncingcats@gmail.com> - 2023-04-18 07:40 +0200
Re: Am I infected with a rootkit? <tomas@tuxteam.de> - 2023-04-18 10:00 +0200
Re: Am I infected with a rootkit? debian-user@howorth.org.uk - 2023-04-18 13:00 +0200
Re: Am I infected with a rootkit? <tomas@tuxteam.de> - 2023-04-18 13:10 +0200
Re: Am I infected with a rootkit? David <bouncingcats@gmail.com> - 2023-04-18 14:10 +0200
Re: Am I infected with a rootkit? <tomas@tuxteam.de> - 2023-04-18 14:30 +0200
Re: Am I infected with a rootkit? songbird <songbird@anthive.com> - 2023-04-18 18:00 +0200
Re: Am I infected with a rootkit? Michel Verdier <mv524@free.fr> - 2023-04-18 18:30 +0200
Re: Am I infected with a rootkit? Andy Smith <andy@strugglers.net> - 2023-04-18 20:40 +0200
Re: Am I infected with a rootkit? Jesper Dybdal <jesper@dybdal.dk> - 2023-04-18 16:00 +0200
Re: Am I infected with a rootkit? David Wright <deblis@lionunicorn.co.uk> - 2023-04-16 16:40 +0200
Re: Am I infected with a rootkit? David Christensen <dpchrist@holgerdanske.com> - 2023-04-17 03:20 +0200
Re: Am I infected with a rootkit? Michel Verdier <mv524@free.fr> - 2023-04-17 17:40 +0200
Re: Am I infected with a rootkit? Stefan Monnier <monnier@iro.umontreal.ca> - 2023-04-17 19:00 +0200
Re: Am I infected with a rootkit? Tim Woodall <debianuser@woodall.me.uk> - 2023-04-17 20:30 +0200
Re: Am I infected with a rootkit? Richmond <dnomhcir@gmx.com> - 2023-04-18 10:40 +0200
Re: Am I infected with a rootkit? Jesper Dybdal <jesper@dybdal.dk> - 2023-04-18 16:00 +0200
Re: Am I infected with a rootkit? Jeremy Ardley <jeremy@ardley.org> - 2023-04-18 16:10 +0200
Re: Am I infected with a rootkit? Charles Curley <charlescurley@charlescurley.com> - 2023-04-18 17:00 +0200
Page 2 of 3 — ← Prev page 1 [2] 3 Next page →
| From | Jesper Dybdal <jd-debian-user@dybdal.dk> |
|---|---|
| Date | 2023-04-16 22:20 +0200 |
| Message-ID | <Glh0R-2ue5-1@gated-at.bofh.it> |
| In reply to | #257309 |
On 2023-04-16 19:35, Thomas Schmitt wrote: > Hi, > > to make this mail on-topic: > > Jesper Dybdal, do you see the riddling lines in file ~/.bash_history > of the superuser ? Yes. > If so: Do you see other strange lines there ? (Do they give more clue ?) No. I stupidly did not save the rest of .bash_history - only the 4 lines. I did, however, take a quick look in the file, and saw nothing conspicuous other than those 4 lines. Thanks, Jesper -- Jesper Dybdal https://www.dybdal.dk
[toc] | [prev] | [next] | [standalone]
| From | Curt <curty@free.fr> |
|---|---|
| Date | 2023-04-17 18:50 +0200 |
| Message-ID | <GlAdb-2FF8-3@gated-at.bofh.it> |
| In reply to | #257291 |
On 2023-04-16, Jesper Dybdal <jd-debian-user@dybdal.dk> wrote: > > On 2023-04-16 15:08, Greg Wooledge wrote: >> On Sun, Apr 16, 2023 at 02:19:34PM +0200, Jesper Dybdal wrote: >>> And there in the bash history were 4 lines that I had not written :-( >> I would initially ask "who else lives with you".... > > So would I - if I didn't know that the few people with physical access > to my apartment, including my wife, haven't the faintest idea that there > is a thing called "md5". Maybe it's some trivial corollary of the infinite monkey theorem, and it's really the dog. --
[toc] | [prev] | [next] | [standalone]
| From | Jesper Dybdal <jd-debian-user@dybdal.dk> |
|---|---|
| Date | 2023-04-16 16:40 +0200 |
| Message-ID | <GlbHP-2qZ1-15@gated-at.bofh.it> |
| In reply to | #257281 |
On 2023-04-16 16:33, David Wright wrote: > On Sun 16 Apr 2023 at 14:19:34 (+0200), Jesper Dybdal wrote: >> The 4 lines were: >>> md5users >>> sp md5users >>> sp /x/md5users >>> ps /x/md5users >> > Just FTR and clarity's sake, are the "> " characters (which my MUA has > unhelpfully doubled by quoting) part of what was typed in the putty > session, or did you type them into the post to make them stand out? They were not part of what was typed, and I did add them to make the lines stand out. Sorry for the unclear text. Here is a correct and clear, I hope, version: ---------------- The 4 lines were: md5users sp md5users sp /x/md5users ps /x/md5users ---------------- End of the 4 lines -- Jesper Dybdal https://www.dybdal.dk
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2023-04-16 17:20 +0200 |
| Message-ID | <Glckx-2rsC-3@gated-at.bofh.it> |
| In reply to | #257292 |
[Multipart message — attachments visible in raw view] — view raw
On Sun, Apr 16, 2023 at 04:39:13PM +0200, Jesper Dybdal wrote: > > On 2023-04-16 16:33, David Wright wrote: > > On Sun 16 Apr 2023 at 14:19:34 (+0200), Jesper Dybdal wrote: > > > The 4 lines were: > > > > md5users > > > > sp md5users > > > > sp /x/md5users > > > > ps /x/md5users > > > > > Just FTR and clarity's sake, are the "> " characters (which my MUA has > > unhelpfully doubled by quoting) part of what was typed in the putty > > session, or did you type them into the post to make them stand out? > They were not part of what was typed, and I did add them to make the lines > stand out. Sorry for the unclear text. > > Here is a correct and clear, I hope, version: > > ---------------- The 4 lines were: > md5users > sp md5users > sp /x/md5users > ps /x/md5users > ---------------- End of the 4 lines Sometimes, some tools rely on a shell at the "other side" to do their job. Emacs's Tramp is known for leaving traces in the shell history, quite possibly abominations like VSCode do their thing in a similar way. That said, the above commands look more like a human not quite knowing what (s)he's doing. If that were an intruder, I'd not worry too much ;-) Cheers -- t
[toc] | [prev] | [next] | [standalone]
| From | David Wright <deblis@lionunicorn.co.uk> |
|---|---|
| Date | 2023-04-18 06:50 +0200 |
| Message-ID | <GlLrX-2Muy-5@gated-at.bofh.it> |
| In reply to | #257292 |
On Sun 16 Apr 2023 at 16:39:13 (+0200), Jesper Dybdal wrote: > On 2023-04-16 16:33, David Wright wrote: > > On Sun 16 Apr 2023 at 14:19:34 (+0200), Jesper Dybdal wrote: > > > The 4 lines were: > > > > md5users > > > > sp md5users > > > > sp /x/md5users > > > > ps /x/md5users > > > > > Just FTR and clarity's sake, are the "> " characters (which my MUA has > > unhelpfully doubled by quoting) part of what was typed in the putty > > session, or did you type them into the post to make them stand out? > They were not part of what was typed, and I did add them to make the > lines stand out. Sorry for the unclear text. > > Here is a correct and clear, I hope, version: > > ---------------- The 4 lines were: > md5users > sp md5users > sp /x/md5users > ps /x/md5users > ---------------- End of the 4 lines OK, you wrote that you "pressed up-arrow a few times. And there in the bash history were 4 lines …". If those 4 lines were not the first things to appear when you pressed up-arrow, then I would assume that the commands you typed /just/ before you went out with the dog were the first lines to appear, and then your 4 lines after more up-arrows. If that's the case, then your 4 lines could have been typed in a previous login as root, and that could have been some time ago. They would have been languishing at the end of the file /root/.bash_history before you logged in as root this time. There is an option to timestamp entries in the history file. I've never used it, nor heard of its being used. That might disambiguate things if you ever suspect it might happen again. Cheers, David.
[toc] | [prev] | [next] | [standalone]
| From | David <bouncingcats@gmail.com> |
|---|---|
| Date | 2023-04-18 07:40 +0200 |
| Message-ID | <GlMel-2N10-9@gated-at.bofh.it> |
| In reply to | #257341 |
On Tue, 18 Apr 2023 at 04:42, David Wright <deblis@lionunicorn.co.uk> wrote: > There is an option to timestamp entries in the history file. I've > never used it, nor heard of its being used. That might disambiguate > things if you ever suspect it might happen again. Hi, on my machines I use Bash as interactive shell, with: HISTTIMEFORMAT=: %Y%m%d_%H%M%S ; That provides a couple of benefits: 1) it writes a commented Unix timestamp with each addition to the ~/.bash_history file, so that the history file not only logs what commands were run interactively, but also when. 2) when I run the 'history' command, the outpt is formatted like this: 501 : 20230418_151124 ; help history 502 : 20230418_151406 ; env 503 : 20230418_151749 ; history The colon and semicolon allow the timestamp to function as a no-operation command. That means that history expansion can still function, for example entering !502 interactively will run line number 502, but only the 'env' that comes after the semicolon will have any effect.
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2023-04-18 10:00 +0200 |
| Message-ID | <GlOpP-2Oi2-1@gated-at.bofh.it> |
| In reply to | #257343 |
[Multipart message — attachments visible in raw view] — view raw
On Tue, Apr 18, 2023 at 05:29:43AM +0000, David wrote: > On Tue, 18 Apr 2023 at 04:42, David Wright <deblis@lionunicorn.co.uk> wrote: > > > There is an option to timestamp entries in the history file. I've > > never used it, nor heard of its being used. That might disambiguate > > things if you ever suspect it might happen again. > > Hi, on my machines I use Bash as interactive > shell, with: > HISTTIMEFORMAT=: %Y%m%d_%H%M%S ; > > That provides a couple of benefits: > > 1) it writes a commented Unix timestamp with > each addition to the ~/.bash_history file, so that > the history file not only logs what commands were > run interactively, but also when. > > 2) when I run the 'history' command, the outpt > is formatted like this: > 501 : 20230418_151124 ; help history > 502 : 20230418_151406 ; env > 503 : 20230418_151749 ; history > The colon and semicolon allow the timestamp > to function as a no-operation command. At least in bash, this doesn't seem necessary, as you are only seeing an external representation: internally, bash keeps the timestamp separate (as happens to the seq number, too). In the external file, the timestamps are kept as #-comments in separate lines (with the UNIX timestamps in them). > That means that history expansion > can still function, for example entering !502 > interactively will run line number 502, but > only the 'env' that comes after the semicolon > will have any effect. I tried it out, and this also works with a "naked" timestamp, without the : ... ; wrapping. Caveat: I only tried with bash. Cheers -- t
[toc] | [prev] | [next] | [standalone]
| From | debian-user@howorth.org.uk |
|---|---|
| Date | 2023-04-18 13:00 +0200 |
| Message-ID | <GlRe1-2Q1C-3@gated-at.bofh.it> |
| In reply to | #257344 |
<tomas@tuxteam.de> wrote: > On Tue, Apr 18, 2023 at 05:29:43AM +0000, David wrote: > > On Tue, 18 Apr 2023 at 04:42, David Wright > > <deblis@lionunicorn.co.uk> wrote: > > > There is an option to timestamp entries in the history file. I've > > > never used it, nor heard of its being used. That might > > > disambiguate things if you ever suspect it might happen again. > > > > Hi, on my machines I use Bash as interactive > > shell, with: > > HISTTIMEFORMAT=: %Y%m%d_%H%M%S ; > > > > That provides a couple of benefits: > > > > 1) it writes a commented Unix timestamp with > > each addition to the ~/.bash_history file, so that > > the history file not only logs what commands were > > run interactively, but also when. > > > > 2) when I run the 'history' command, the outpt > > is formatted like this: > > 501 : 20230418_151124 ; help history > > 502 : 20230418_151406 ; env > > 503 : 20230418_151749 ; history > > The colon and semicolon allow the timestamp > > to function as a no-operation command. > > At least in bash, this doesn't seem necessary, as you are > only seeing an external representation: internally, bash > keeps the timestamp separate (as happens to the seq number, > too). > > In the external file, the timestamps are kept as #-comments > in separate lines (with the UNIX timestamps in them). bash seems to treat root and a normal user differently. > > That means that history expansion > > can still function, for example entering !502 > > interactively will run line number 502, but > > only the 'env' that comes after the semicolon > > will have any effect. > > I tried it out, and this also works with a "naked" timestamp, > without the : ... ; wrapping. > > Caveat: I only tried with bash. > > Cheers
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2023-04-18 13:10 +0200 |
| Message-ID | <GlRnI-2Qlc-5@gated-at.bofh.it> |
| In reply to | #257347 |
[Multipart message — attachments visible in raw view] — view raw
On Tue, Apr 18, 2023 at 11:51:42AM +0100, debian-user@howorth.org.uk wrote: > <tomas@tuxteam.de> wrote: [...] > > At least in bash, this doesn't seem necessary, as you are > > only seeing an external representation: internally, bash > > keeps the timestamp separate (as happens to the seq number, > > too). > > > > In the external file, the timestamps are kept as #-comments > > in separate lines (with the UNIX timestamps in them). > > bash seems to treat root and a normal user differently. On my box, history, .bash_history and HISTTIMEFORMAT behave as I described both for root and for a regular user. Just to be sure: # tomas@trotzki:~$ bash --version # GNU bash, version 5.1.4(1)-release (x86_64-pc-linux-gnu) # Copyright (C) 2020 Free Software Foundation, Inc. # License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html> # # This is free software; you are free to change and redistribute it. # There is NO WARRANTY, to the extent permitted by law. Cheers -- t
[toc] | [prev] | [next] | [standalone]
| From | David <bouncingcats@gmail.com> |
|---|---|
| Date | 2023-04-18 14:10 +0200 |
| Message-ID | <GlSjL-2QWe-3@gated-at.bofh.it> |
| In reply to | #257344 |
On Tue, 18 Apr 2023 at 07:51, <tomas@tuxteam.de> wrote: > On Tue, Apr 18, 2023 at 05:29:43AM +0000, David wrote: > > On Tue, 18 Apr 2023 at 04:42, David Wright <deblis@lionunicorn.co.uk> wrote: > > > There is an option to timestamp entries in the history file. I've > > > never used it, nor heard of its being used. That might disambiguate > > > things if you ever suspect it might happen again. > > > > Hi, on my machines I use Bash as interactive > > shell, with: > > HISTTIMEFORMAT=: %Y%m%d_%H%M%S ; > > > > That provides a couple of benefits: > > > > 1) it writes a commented Unix timestamp with > > each addition to the ~/.bash_history file, so that > > the history file not only logs what commands were > > run interactively, but also when. > > > > 2) when I run the 'history' command, the outpt > > is formatted like this: > > 501 : 20230418_151124 ; help history > > 502 : 20230418_151406 ; env > > 503 : 20230418_151749 ; history > > The colon and semicolon allow the timestamp > > to function as a no-operation command. > > At least in bash, this doesn't seem necessary, as you are > only seeing an external representation: internally, bash > keeps the timestamp separate (as happens to the seq number, > too). Hi, it could well be unnecessary, I haven't played with it for a long time. I'm sure that there would have been some reason at the time why I chose to configure it that way, but it is so many years ago that I can't recall the reason. Guessing, it could just have been that I was lazy and doing something odd. Perhaps I wanted to dump the history output into a file, preserve the timestamps for some long-forgotten reason, and also put a shebang at the top of the file and run it again with minimal editing. Or maybe I wanted a known delimiter that I could strip automatically from the history output. I dunno. It also would have been several Bash versions ago, Bash 2 or 3, so perhaps the behaviour changed since I configured it. Anyway, if it isn't necessary now, there's no reason for me to advocate doing that, so I appreciate that you have let everyone know about that.
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2023-04-18 14:30 +0200 |
| Message-ID | <GlSD8-2R3b-1@gated-at.bofh.it> |
| In reply to | #257349 |
[Multipart message — attachments visible in raw view] — view raw
On Tue, Apr 18, 2023 at 11:59:58AM +0000, David wrote: > On Tue, 18 Apr 2023 at 07:51, <tomas@tuxteam.de> wrote: > > On Tue, Apr 18, 2023 at 05:29:43AM +0000, David wrote: [...] > > > The colon and semicolon allow the timestamp > > > to function as a no-operation command. > > > > At least in bash, this doesn't seem necessary, as you are > > only seeing an external representation: internally, bash > > keeps the timestamp separate (as happens to the seq number, > > too). > > Hi, it could well be unnecessary, I haven't played with it > for a long time. [...] > It also would have been several Bash versions ago, Bash 2 or 3, so > perhaps the behaviour changed since I configured it. > > Anyway, if it isn't necessary now, there's no reason for me to advocate > doing that, so I appreciate that you have let everyone know about that. Definitely. I just pointed that out as a request for discussion. Perhaps this isn't portable across shells or even different versions of bash. So caveat emptor :) Cheers and thanks -- I didn't know about HISTTIMEFORMAT before! -- t
[toc] | [prev] | [next] | [standalone]
| From | songbird <songbird@anthive.com> |
|---|---|
| Date | 2023-04-18 18:00 +0200 |
| Message-ID | <GlVUl-2SWQ-3@gated-at.bofh.it> |
| In reply to | #257350 |
<tomas@tuxteam.de> wrote: ... > Definitely. I just pointed that out as a request for discussion. > Perhaps this isn't portable across shells or even different > versions of bash. So caveat emptor :) > > Cheers and thanks -- I didn't know about HISTTIMEFORMAT before! just as an aside for those who think about this sort of thing. :) i like to start with a known state including the shell history so upon starting up a terminal i determine what commands i want in the history by detecting which directory i'm in (which tells me which project i'm working on). it's very easy then for me to start things by using the !<number> or !<abbrv>. i also do not like history stuff hanging around so i may attempt to clear things out upon logging out or shutting down but since some crashes can happen i do not rely upon that being 100%. which is why when i do start up i set things up how i like and do clear the history at that point (before putting the commands in i want). songbird
[toc] | [prev] | [next] | [standalone]
| From | Michel Verdier <mv524@free.fr> |
|---|---|
| Date | 2023-04-18 18:30 +0200 |
| Message-ID | <GlWno-2TlQ-3@gated-at.bofh.it> |
| In reply to | #257362 |
Le 18 avril 2023 songbird a écrit : > i like to start with a known state including the shell history > so upon starting up a terminal i determine what commands i want > in the history by detecting which directory i'm in (which tells > me which project i'm working on). it's very easy then for me > to start things by using the !<number> or !<abbrv>. I recently learned the ctrl-r key which launch a regex search in history. It's more powerful than !<abbrv> as it search the full lines so not only commands but also parameters.
[toc] | [prev] | [next] | [standalone]
| From | Andy Smith <andy@strugglers.net> |
|---|---|
| Date | 2023-04-18 20:40 +0200 |
| Message-ID | <GlYpb-2UCC-1@gated-at.bofh.it> |
| In reply to | #257363 |
Hello, On Tue, Apr 18, 2023 at 06:22:16PM +0200, Michel Verdier wrote: > I recently learned the ctrl-r key which launch a regex search in > history. It's more powerful than !<abbrv> as it search the full > lines so not only commands but also parameters. Now step in to the late 2010s and look into "fzf" 😀 (It is packaged in Debian) Cheers, Andy -- https://bitfolk.com/ -- No-nonsense VPS hosting
[toc] | [prev] | [next] | [standalone]
| From | Jesper Dybdal <jesper@dybdal.dk> |
|---|---|
| Date | 2023-04-18 16:00 +0200 |
| Message-ID | <GlU2d-2RNB-1@gated-at.bofh.it> |
| In reply to | #257343 |
On 2023-04-18 07:29, David wrote: > On Tue, 18 Apr 2023 at 04:42, David Wright <deblis@lionunicorn.co.uk> wrote: > >> There is an option to timestamp entries in the history file. I've >> never used it, nor heard of its being used. That might disambiguate >> things if you ever suspect it might happen again. > Hi, on my machines I use Bash as interactive > shell, with: > HISTTIMEFORMAT=: %Y%m%d_%H%M%S ; > > That provides a couple of benefits: ... Thanks to David, David, Tomas, and debian-user@howorth.org.uk for the suggestion of using time stamps on the history lines. I intend to do that in the future. -- Jesper Dybdal https://www.dybdal.dk
[toc] | [prev] | [next] | [standalone]
| From | David Wright <deblis@lionunicorn.co.uk> |
|---|---|
| Date | 2023-04-16 16:40 +0200 |
| Message-ID | <GlbHP-2qZ1-7@gated-at.bofh.it> |
| In reply to | #257281 |
On Sun 16 Apr 2023 at 14:19:34 (+0200), Jesper Dybdal wrote: > And there in the bash history were 4 lines that I had not written :-( > > I am certain that nobody had been in my apartment while I was gone. > And even if they had, nobody with a key to my apartment would dream of > writing things like the 4 lines that I found in the history file. > > The 4 lines were: > > md5users > > sp md5users > > sp /x/md5users > > ps /x/md5users > There is no file named "md5users" or directory named "/x" or command > named "sp" on the Debian machine. Just FTR and clarity's sake, are the "> " characters (which my MUA has unhelpfully doubled by quoting) part of what was typed in the putty session, or did you type them into the post to make them stand out? The reason I ask is that most people have their PS2 set to "> ", suggesting that these might have been some sort of continuation— of what, we don't know. Cheers, David.
[toc] | [prev] | [next] | [standalone]
| From | David Christensen <dpchrist@holgerdanske.com> |
|---|---|
| Date | 2023-04-17 03:20 +0200 |
| Message-ID | <GllHb-2x2t-1@gated-at.bofh.it> |
| In reply to | #257281 |
On 4/16/23 05:19, Jesper Dybdal wrote:
> I have a Debian pc functioning as router, firewall, file server, name
> server, webserver, ...
> It has very recently been upgraded to Bullseye.
>
> On the internal network I have a Windows 10 pc.
> And there in the bash history were 4 lines that I had not written :-(
>> md5users
>> sp md5users
>> sp /x/md5users
>> ps /x/md5users
On 4/16/23 07:30, Jesper Dybdal wrote:
> ... I really need to be able to run ssh [on Windows to] administer
> [the Debian] machine (which normally has neither keyboard nor
> monitor).
What about installing a KVM switch and administering the Debian computer
from the console?
If the two computers are separated, you could use a KVM extender and put
the KVM switch near the Windows computer. Or, you could get networked
KVM equipment.
That said, using one computer as router, firewall, file server, name
server, web server, and more represents "all of your eggs in one
basket". I suggest using dedicated hardware for networking, network
segmentation (e.g. DMZ), and kernel or hypervisor compartmentalization
of services. Qubes looks very appealing:
https://www.qubes-os.org/
David
[toc] | [prev] | [next] | [standalone]
| From | Michel Verdier <mv524@free.fr> |
|---|---|
| Date | 2023-04-17 17:40 +0200 |
| Message-ID | <Glz7r-2F3t-1@gated-at.bofh.it> |
| In reply to | #257315 |
Le 17 avril 2023 David Christensen a écrit : > That said, using one computer as router, firewall, file server, name server, > web server, and more represents "all of your eggs in one basket". I suggest > using dedicated hardware for networking, network segmentation (e.g. DMZ), and > kernel or hypervisor compartmentalization of services. Qubes looks very > appealing: What are its advantages vs debian ? Debian can chroot most services. Some are chrooted by default (postfix, etc). And you can use Xen and tor on debian.
[toc] | [prev] | [next] | [standalone]
| From | Stefan Monnier <monnier@iro.umontreal.ca> |
|---|---|
| Date | 2023-04-17 19:00 +0200 |
| Message-ID | <GlAmR-2FId-9@gated-at.bofh.it> |
| In reply to | #257315 |
> That said, using one computer as router, firewall, file server, name server,
> web server, and more represents "all of your eggs in one basket". I suggest
> using dedicated hardware for networking, network segmentation (e.g. DMZ),
> and kernel or hypervisor compartmentalization of services.
Dedicated hardware has its upsides, indeed, but it also
has its downsides (e.g. in terms of impact to the planet).
Stefan
[toc] | [prev] | [next] | [standalone]
| From | Tim Woodall <debianuser@woodall.me.uk> |
|---|---|
| Date | 2023-04-17 20:30 +0200 |
| Message-ID | <GlBLX-2GF4-5@gated-at.bofh.it> |
| In reply to | #257330 |
On Mon, 17 Apr 2023, Stefan Monnier wrote: >> That said, using one computer as router, firewall, file server, name server, >> web server, and more represents "all of your eggs in one basket". I suggest >> using dedicated hardware for networking, network segmentation (e.g. DMZ), >> and kernel or hypervisor compartmentalization of services. > > Dedicated hardware has its upsides, indeed, but it also > has its downsides (e.g. in terms of impact to the planet). > This is very true. I switched to using one of these: https://www.asrockrack.com/general/productdetail.asp?Model=J1900D2Y in a xen configuration, from multiple hardware - but multiple services on one hardware instance. it's low power and fanless and has built in IPMI. For me that ticks all the boxes I need. Having each of nameserver, dhcp server, web server, firewall, "file server"[1] etc, running on separate guests makes upgrading so much simpler too. I used to dread upgrades, now they're relatively painless. [1] I don't really run a fileserver but I do run iscsi targets.
[toc] | [prev] | [next] | [standalone]
Page 2 of 3 — ← Prev page 1 [2] 3 Next page →
Back to top | Article view | linux.debian.user
csiph-web