Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
security status after install
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
nss
Guru
Guru


Joined: 04 Oct 2004
Posts: 389

PostPosted: Fri Jan 13, 2006 8:00 am    Post subject: security status after install Reply with quote

I was wondering how secure gentoo is after installing. I was reading today about a little experiment where a computer was put online after a fresh install and was attacked after just four minutes by malicious software. I'd give more details on the article (it was in a back issue of MIT's Technology Review) but I don't have it nearby right now. It went on to say how common Internet attacks are, etc. etc. The article brought about extra concern for my newly installed system. After installing gentoo, I did not do much (or anything) in the way of security. Instead, I went right to installing third party software through portage. I've since been using the Internet regularly (mostly these forums and gmail, but other sites also). How concerned should I be?

Is freenode safe to use? I saw that it had a severe nuisancebot attack. Does this mean insecurity for it's users?
_________________
gentoo good to be true
Back to top
View user's profile Send private message
bec
Apprentice
Apprentice


Joined: 30 Sep 2004
Posts: 221
Location: Cali - Colombia

PostPosted: Fri Jan 13, 2006 8:53 am    Post subject: Reply with quote

If your machine is not a gateway you could simply follow:

https://forums.gentoo.org/viewtopic.php?t=289163

For a more thorough approach look in:

http://www.gentoo.org/doc/en/gentoo-security.xml

I don't know about freenode security :)
_________________
abe
Back to top
View user's profile Send private message
DerCorny
Retired Dev
Retired Dev


Joined: 26 Jun 2005
Posts: 14
Location: Oberhausen, Germany

PostPosted: Sat Jan 14, 2006 1:03 pm    Post subject: Reply with quote

Gentoo should be pretty safe after an install. Usually portage is synced during the install, meaning that all packages which will be installed are up-to-date and hopefully secure. (In contrast to that one OS hailing from redmond, usually installed by using a more than 3yrs old CD with no fixes at all)

Freenode is as safe as your IRC client - if you use a well known one, it's probably well audited and secure.
_________________
There is nothing in the world more helpless and irresponsible than a man in the depths of an ether binge...
Back to top
View user's profile Send private message
nss
Guru
Guru


Joined: 04 Oct 2004
Posts: 389

PostPosted: Tue Jan 17, 2006 9:04 am    Post subject: Reply with quote

What does the appearance of this nuisancebot mean for the users of freenode?
_________________
gentoo good to be true
Back to top
View user's profile Send private message
DerCorny
Retired Dev
Retired Dev


Joined: 26 Jun 2005
Posts: 14
Location: Oberhausen, Germany

PostPosted: Wed Jan 18, 2006 12:59 pm    Post subject: Reply with quote

They aren't a security threat for clients of the network, just annoying. They join big chans and post URLs they want you to visit or spam you in a query. Freenode staff does a pretty good job to keep them out, but thats not always possible. I guess every big IRC network has similar problems.

Btw, i'm in like 15chans in freenode and never had any problems with those bots.
_________________
There is nothing in the world more helpless and irresponsible than a man in the depths of an ether binge...
Back to top
View user's profile Send private message
groovin
Guru
Guru


Joined: 07 Feb 2004
Posts: 429
Location: California, USA

PostPosted: Wed Jan 18, 2006 6:39 pm    Post subject: Reply with quote

DerCorny wrote:
(In contrast to that one OS hailing from redmond, usually installed by using a more than 3yrs old CD with no fixes at all)


with winXP, at least the firewall is on... but with 2k, you wont even have enough time to download and install zonealarm before your comp is infected (assuming no hw firewall). youd have to get zonealarm on a disk, install, then go online to get updates. they should add a footnote like that to their installation guide.
Back to top
View user's profile Send private message
sirtalon42
Tux's lil' helper
Tux's lil' helper


Joined: 09 Aug 2005
Posts: 79

PostPosted: Wed Jan 18, 2006 6:46 pm    Post subject: Reply with quote

groovin wrote:
DerCorny wrote:
(In contrast to that one OS hailing from redmond, usually installed by using a more than 3yrs old CD with no fixes at all)


with winXP, at least the firewall is on... but with 2k, you wont even have enough time to download and install zonealarm before your comp is infected (assuming no hw firewall). youd have to get zonealarm on a disk, install, then go online to get updates. they should add a footnote like that to their installation guide.


Only WindowsXP SP2 has the firewall on by default. SP1/original didn't.
Back to top
View user's profile Send private message
docster
n00b
n00b


Joined: 17 Jan 2006
Posts: 27

PostPosted: Wed Jan 18, 2006 6:52 pm    Post subject: Reply with quote

Hehe, well, once apon a time we installed Mandrake Corporate Server to play around with at the data center. It was late one night and we just installed from the cd and did'nt really have time to update it properly. The following morning it had a root kit on it with an irc bot running :D
Back to top
View user's profile Send private message
groovin
Guru
Guru


Joined: 07 Feb 2004
Posts: 429
Location: California, USA

PostPosted: Thu Jan 19, 2006 4:25 am    Post subject: Reply with quote

docster wrote:
Hehe, well, once apon a time we installed Mandrake Corporate Server to play around with at the data center. It was late one night and we just installed from the cd and did'nt really have time to update it properly. The following morning it had a root kit on it with an irc bot running :D


yeah, no system is perfect... but my friends once left an unpatched windows box online over night after a fresh install... by morning we saw that the machine had been hacked several times and already had a good amount of pR0n on it!
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum