file:/mnt/floppy does not exist
I have just installed knoppix 3.6 to my hard drive I am trying to open an office 2000 document from a floppy but when in OO I use file>open but cannot see anything when I try to go via floppy
I cannot open any disks I get the above msg file:/mnt/floppy...
Help appreciated as this is my girlfriends resume and i am copping grief about OS change I am happy tho :D
No floppy gives same msg if i use floppy desktop icon
How do i mount the floppy?
Re: No floppy gives same msg if i use floppy desktop icon
Quote:
Originally Posted by flebber
How do i mount the floppy?
'sudo mount /dev/fd0 ' should do it but I suspect something else is wrong & it's not detecting your floppy drive.
Do you have this line in your /etc/fstab file?
Code:
/dev/fd0 /floppy vfat defaults,user,noauto,showexec,umask=022 0 0
Are you getting any error messages?
getting back root after being hacked
To the list;
I have lost root a long time ago. I just get by, using a few different machines and try to keep them off the net. Knoppix can be hacked. I think that they get access to root remotely, then they shut down the security. They can then tamper with all kinds of things. Sound card, PCI card, BIOS settings and prevent a number of applications from running or running right.
You would think that the ramdisk would flush everything but it doesn't. I removed my hard drive and so I run solely on the CD. It at least functions whereas HD's don't last one day on this machine. They are almost immediately hacked off the net. Usually it takes about a month to hack down my Knoppix live CD's.I have been using a BSD live CD and Knoppix 3.6 to reset my settings after they have been heavily hacked. I primarity use Knoppix 3.3 on the net and load up the others offline and then return with Knoppix 3.3 and just allow them to hack that version.This doesn't always work but I have these little tricks that keep me online but I am no programmer and so eventually I am shutdown but then there are new CD's to try. Then I am back into the game again and I start all over with this hacker. I don't know him/her and have no clue as to what its about. Some kind of game, maybe but this is how I cope with it.
Now I said I lost root a long time ago and its true. This is because of the matter of being able to create a persistent directory. Hackers know this and so they create one and lock you out. Then they make funky settings and whatever???
To get back root is a key to this problem and then secure it so that these file deletions do not occur. This also means no remote root. How can we get back root and deny all remote access to this with Knoppix?
let me know
thanks again
[email protected]
respond to root message with this e-mail
To the list;
I left the last message and I misspelled my e-mail address.
Respond to the root message to:
[email protected]
thanks again
there is more than a firewall problem hee
11/11/04
To the list;
I entered this commend into the Knoppix console and this is the result. I have no problem with doing this for any requsst in oorder to learn more about this. Take a look at the output.This is a typical result that I get for every shell request. Nothing ever works on my shell. Its like its disabled. With this in mind lets throw out what I know about this.
I have been stalked for years by this person and I really still don't know who it is but I do work as a worker advocate so there are enemies to me in gov't and business.I shouldn't be attacked because I only advocate the true status of laws and rules as they now exist and do not seek different laws..I get into problems in the fact that laws that do benefit the worker are not at all adhered to. I am sometimes anomously attacked and so where is it coming from???? I don't care to get into this for now. The thing we have at hand is this remote root problem.I will continue with this series in order to bring some sense to this but first a starting point.
Now I have this computer and it got a trojan horse in it. I didn't know enough to expel it. I tried to get files, programs and even other OS's. This guy owned me and I couldn't shake him. When I put programs in they do not execute. I just got fed up and started using live CD's. They quickly go to hell but I mostly just check e-mail and surf so it is not a major loss but it is a pain at times too. I do at times work at trying to figure out the programming but he clearly has me over a barrel over this. I have hung in there against him and all of what he knows for the longest time.Its a tribute to what I know but I would like to get rid of this person now and so in a way I am appealling to the computer community to help purge this stalker from my life. I will provide data as you need it so bear with me.
Now the hacker has root so he is the general. I have little say in what is happening and I am not fully in control.This talk of putting up a firewall is his decision until I can throw him out. Got some ideas?
This belief that Knoppix or any other version of Linux/Unix can't be hacked is total crap. These hackers call pull dirty code on any version of any OS like you make selections for a MP3 file. They get root and can pipe it in and you can't stop it until you gain total control of root. How can you when they own certain progroms like telnet, ssh and others?
let me know what you think and maybe we can discuss a plan
thanks and guess what I will be offering more on this but I am going out now so later
about your suggestion this is the output
knoppix@ttyp0[knoppix]$ ls /mnt/auto/floppy
ls: /mnt/auto/floppy: No such file or directory
knoppix@ttyp0[knoppix]$
thanks again
finder
Re: there is more than a firewall problem hee
Quote:
Originally Posted by finder
11/11/04
....... this is the output
knoppix@ttyp0[knoppix]$ ls /mnt/auto/floppy
ls: /mnt/auto/floppy: No such file or directory
knoppix@ttyp0[knoppix]$
thanks again
finder
This is a normal output for this command if you do not have a disk in the floppy drive. The directory /mnt/auto/floppy is created by the automounter only when there is a disk in the drive.
If you are getting this result when you have a floppy disk in the drive it indicates that your automounter is not operating correctly.
If you feel that your system is being hacked, first change your root and user passwords. It would be a rare trojan that could keep up with a regularly changed password.
When you say, 'nothing ever works in my shell', what have you tried?
Try this:
ls /etc
You should get a directory listing of your /etc directory.
Try this
cat /etc/fstab
you should get a listing of you /etc/fstab file.
Try this
konqueror
You should get a couple of errors because you are trying to start an X (graphical interface) application from shell but konqueror should start.
try this
ping -c 5 216.239.57.99
you should get an output like this:
Quote:
knoppix@2[knoppix]$ ping -c 5 216.239.57.99
PING 216.239.57.99 (216.239.57.99): 56 data bytes
64 bytes from 216.239.57.99: icmp_seq=0 ttl=239 time=75.7 ms
64 bytes from 216.239.57.99: icmp_seq=1 ttl=239 time=69.4 ms
64 bytes from 216.239.57.99: icmp_seq=2 ttl=239 time=69.6 ms
64 bytes from 216.239.57.99: icmp_seq=3 ttl=239 time=69.4 ms
64 bytes from 216.239.57.99: icmp_seq=4 ttl=239 time=71.3 ms
--- 216.239.57.99 ping statistics ---
5 packets transmitted, 5 packets received, 0% packet loss
round-trip min/avg/max = 69.4/71.0/75.7 ms
knoppix@2[knoppix]$
216.239.57.99 is the ip address for google. Ping tests your internet connection.
try this:
cat /etc/sudoers
You should get this
cat: /etc/sudoers: Permission denied
because the sudoers file is readable only by root.
Now try this:
sudo cat /etc/sudoers
You should get this:
Quote:
# sudoers file.
#
# This file MUST be edited with the "visudo" command as root.
#
# See the man page for details on how to write a sudoers file.
#
# Host alias specification
# User alias specification
# Cmnd alias specification
# User privilege specification
root ALL=(ALL) ALL
# KNOPPIX WARNING: This allows the unprivileged knoppix user to start commands as root
# KNOPPIX WARNING: This is totally insecure and (almost) makes knoppix a second root account.
# KNOPPIX WARNING: Never allow external access to the knoppix user!!!
knoppix ALL=NOPASSWD: ALL
more regarding a hacked system that won't allow mnt fd0
To the list;
Now I will try the suggestions and see where they go. It is not possible to put up a firewall after being hacked unless you rid the computer of the bad code that may prevent your executing the firewall program. The first thing a hacker will do is shut down your firewall and then put in code that prevents your executing the program. I have heard that in the past all they had to do is get you to open a file that was only 35K but now that size is even less at 15K. A simple e-mail is what I think did me in a few years ago. I think that the original file created a telent or ssh connection and then a pipe is established with bad code after discovering what OS is in use.
Sadly the dirty code is not created by the punks that send them they are created and posted on the web by people or students that excel at programming and find flaws in the OS's. They write binaries and then some punk picks it up and uses it against someone that they may or may not know.
I did get this output for su when I entered it into a shell..I thought I could delete ssh and see what would happen.
knoppix@ttyp1[knoppix]$ su
root@ttyp1[knoppix]# delete file:/KNOPPIX/usr/bin/ssh
bash: delete: command not found
root@ttyp1[knoppix]# delete file:/KNOPPIX/usr/bin/ssh
bash: delete: command not found
root@ttyp1[knoppix]# del file:/KNOPPIX/usr/bin/ssh
bash: del: command not found
root@ttyp1[knoppix]# mnt fd0
bash: mnt: command not found
root@ttyp1[knoppix]# mount fd0
mount: can't find fd0 in /etc/fstab or /etc/mtab
root@ttyp1[knoppix]#
I also tried this.
knoppix@ttyp0[knoppix]$ sudo /etc/init.d/autofs status
Configured Mount Points:
------------------------
/usr/sbin/automount --timeout=2 /mnt/auto program /etc/automount.sh
Active Mount Points:
--------------------
/usr/sbin/automount --pid-file=/var/run/autofs/_:mnt_:auto.pid --timeout=2 /mnt/auto program /etc/automount.sh
knoppix@ttyp0[knoppix]$ sudo /etc/init.d/autofs reload
Reloading automounter: checking for changes...done.
Starting automounter: /mnt/auto.
knoppix@ttyp0[knoppix]$ mount fd0
mount: can't find fd0 in /etc/fstab or /etc/mtab
knoppix@ttyp0[knoppix]$
One thing that I felt would be a good suggestion is to get some idea of thr programming size that exists on the disk and to then have a test that runs on the installing computer to see if that is exactly the size of what was installed or if there is some other code that is present when KNOPPIX loads. Like a checksum test.
Second thing is if I have bad code then where is it? I took out my hard drive and so where would it be??? I don't believe it is on the disk itself because I don't have a CD-W drive. Read only so that is out.Then we have memory. Well when you turn off your computer you supposedly flush the contents of the ram. I think that for the most part this is true. I had a hacking problem and so I turned off the computer and physically removed all the ram fully from the computer and then later replaced it again.It made no difference. Then that leaves the systemboard/motherboard as the only place the bad code could be. Now I also have a cable modem and a syslink router. Do these devices store code and what kind? Dould they or the computer BIOS store any bad code. I don't get the proper color on my screen when I check my BIOS and so I think it is hacked. Still where would it be and it is possible to reflash remotely a BIOS so possibly did this happen and what effect could it have?
any ideas?
let me know
finder
[email protected]
those suggestions checked out
To the list;
Sometimes getting root is not so easy.
knoppix@ttyp1[knoppix]$ /dev/fd0
bash: /dev/fd0: Permission denied
knoppix@ttyp1[knoppix]$ su
root@ttyp1[knoppix]# /dev/fd0
bash: /dev/fd0: Permission denied
root@ttyp1[knoppix]# su
root@ttyp1[knoppix]# passwd
Enter new UNIX password:
Retype new UNIX password:
passwd: password updated successfully
root@ttyp1[knoppix]# /dev/fd0
bash: /dev/fd0: Permission denied
root@ttyp1[knoppix]# su
root@ttyp1[knoppix]# passwd
Enter new UNIX password:
Retype new UNIX password:
passwd: password updated successfully
root@ttyp1[knoppix]# /dev/fd0
bash: /dev/fd0: Permission denied
root@ttyp1[knoppix]#
knoppix@ttyp1[knoppix]$ code
bash: code: command not found
knoppix@ttyp1[knoppix]$ sudo password knoppix
sudo: password: command not found
knoppix@ttyp1[knoppix]$ sudo password
sudo: password: command not found
knoppix@ttyp1[knoppix]$ su
root@ttyp1[knoppix]# sudo password
sudo: password: command not found
root@ttyp1[knoppix]# sudo password knoppix
sudo: password: command not found
root@ttyp1[knoppix]#
So I attempt to check out the sudos and do the find, search for sudos and I got three files and this is what it reads out.
Name In Subdirectory size modified permissions first matching line
sudoers KNOPPIX/ect/ 560 08/23/01 09:14 pm Inaccessible
sudoers KNOPPIX/usr/share/docs/s...3,966 09/03/03 06:33 am read only
sudoers ect/ 560 08/23/01 09:14 pm Inaccessible
I went to home and then tried to open either of the two inaccessible files and used gvim to open and at the bottom they tell me that permission denied.
I also get this error box.
Error -Konqueror
X Unable to run the command specified. The file or directory
file:/KNOPPIX/ect/ does not exist
with a floppy disk in the drive
knoppix@ttyp2[knoppix]$ su
root@ttyp2[knoppix]# ls /mnt/auto/floppy
ls: /mnt/auto/floppy: No such file or directory
root@ttyp2[knoppix]#
I tried this
knoppix@ttyp3[knoppix]$ ls /ect
ls: /ect: No such file or directory
knoppix@ttyp3[knoppix]$ su
root@ttyp3[knoppix]# ls /ect
ls: /ect: No such file or directory
root@ttyp3[knoppix]#
knoppix@ttyp0[knoppix]$ cat /ect/fstab
cat: /ect/fstab: No such file or directory
knoppix@ttyp0[knoppix]$ su
root@ttyp0[knoppix]# cat /ect/fstab
cat: /ect/fstab: No such file or directory
root@ttyp0[knoppix]#
with a router and cable modem connected but coax cable to ISP removed I got this output.
knoppix@ttyp0[knoppix]$ ping -c 5 216.239.57.99
PING 216.239.57.99 (216.239.57.99): 56 data bytes
--- 216.239.57.99 ping statistics ---
5 packets transmitted, 0 packets received, 100% packet loss
knoppix@ttyp0[knoppix]$
knoppix@ttyp0[knoppix]$
I will try it again when I re-connect to the net.
other suggestions
knoppix@ttyp1[knoppix]$ cat /ect/sudoers
cat: /ect/sudoers: No such file or directory
knoppix@ttyp1[knoppix]$ su
root@ttyp1[knoppix]# cat /ect/sudoers
cat: /ect/sudoers: No such file or directory
root@ttyp1[knoppix]#
any ideas?
let me know
finder
[email protected]
Re: more regarding a hacked system that won't allow mnt fd0
Quote:
Originally Posted by finder
I did get this output for su when I entered it into a shell..I thought I could delete ssh and see what would happen.
knoppix@ttyp1[knoppix]$ su
root@ttyp1[knoppix]# delete file:/KNOPPIX/usr/bin/ssh
bash: delete: command not found
OK, so 'su' works and you can now become root whenever you need to.
But in Linux the command to delete a file is 'rm' (short for 'remove') not 'delete' or 'del'
And, the location of the file would be 'usr/bin/ssh' not 'KNOPPIX/usr/bin/ssh'
And, if I understand you correctly, you are running from CD so you will not be able to delete this file anyway because the CD is read only so you cannot change anything on it. You should get a 'read only file system error' if you enter the command correctly.
Quote:
root@ttyp1[knoppix]# mnt fd0
bash: mnt: command not found
root@ttyp1[knoppix]# mount fd0
mount: can't find fd0 in /etc/fstab or /etc/mtab
root@ttyp1[knoppix]#
The correct command is 'mount' but you must specify '/dev/fd0' not just fd0.
Quote:
I also tried this.
knoppix@ttyp0[knoppix]$ sudo /etc/init.d/autofs status
Configured Mount Points:
------------------------
/usr/sbin/automount --timeout=2 /mnt/auto program /etc/automount.sh
Active Mount Points:
--------------------
/usr/sbin/automount --pid-file=/var/run/autofs/_:mnt_:auto.pid --timeout=2 /mnt/auto program /etc/automount.sh
knoppix@ttyp0[knoppix]$ sudo /etc/init.d/autofs reload
Reloading automounter: checking for changes...done.
Starting automounter: /mnt/auto.
This looks OK
Quote:
One thing that I felt would be a good suggestion is to get some idea of thr programming size that exists on the disk and to then have a test that runs on the installing computer to see if that is exactly the size of what was installed or if there is some other code that is present when KNOPPIX loads. Like a checksum test.
There is a checksum on the Knoppix download iso's.
Quote:
Second thing is if I have bad code then where is it? I took out my hard drive and so where would it be??? I don't believe it is on the disk itself because I don't have a CD-W drive. Read only so that is out.Then we have memory. Well when you turn off your computer you supposedly flush the contents of the ram. I think that for the most part this is true. I had a hacking problem and so I turned off the computer and physically removed all the ram fully from the computer and then later replaced it again.It made no difference. Then that leaves the systemboard/motherboard as the only place the bad code could be. Now I also have a cable modem and a syslink router. Do these devices store code and what kind? Dould they or the computer BIOS store any bad code. I don't get the proper color on my screen when I check my BIOS and so I think it is hacked. Still where would it be and it is possible to reflash remotely a BIOS so possibly did this happen and what effect could it have?
This is a pretty good analysis and it leads to only one conclusion. At the present time it is highly unlikely that you are being hacked. Modem and router cannot store any code which is capable of being a trojan.
Although you may have been the victim of a hacker at one time, the only reason to suspect something wrong at present is that commands don't work as expected and we are finding that this is often due to incorrectly entered commands, I suggest you study Linux commands thoroughly to prevent errors. An excellent Linux reference book is 'Rute', which can be downloaded from http://www.icon.co.za/~psheer/book/index.html.gz. You will have to put your hard drive back in though, it's too big to fit in memory & you will need some place to store it.
If you reinstall your hard drive then format it using Qtparted running from the Knoppix CD it will be free of any bugs. I suggest also that you partition it into at least two partitions, one for operating system and one for data. That is more secure, a trojan is seldom capable of finding a second partition to attack data there. Qtparted can do the partition too.
Your second post:
Quote:
knoppix@ttyp1[knoppix]$ /dev/fd0
bash: /dev/fd0: Permission denied
knoppix@ttyp1[knoppix]$ su
root@ttyp1[knoppix]# /dev/fd0
bash: /dev/fd0: Permission denied
root@ttyp1[knoppix]# su
root@ttyp1[knoppix]# passwd
Enter new UNIX password:
Retype new UNIX password:
passwd: password updated successfully
root@ttyp1[knoppix]# /dev/fd0
bash: /dev/fd0: Permission denied
root@ttyp1[knoppix]# su
root@ttyp1[knoppix]# passwd
Enter new UNIX password:
Retype new UNIX password:
passwd: password updated successfully
root@ttyp1[knoppix]# /dev/fd0
bash: /dev/fd0: Permission denied
root@ttyp1[knoppix]#
Here again you must enter 'mount /dev/fd0' not just '/dev/fd0' and you will get an error message if there is no disk in the floppy drive.
Quote:
knoppix@ttyp1[knoppix]$ code
bash: code: command not found
knoppix@ttyp1[knoppix]$ sudo password knoppix
sudo: password: command not found
knoppix@ttyp1[knoppix]$ sudo password
sudo: password: command not found
knoppix@ttyp1[knoppix]$ su
root@ttyp1[knoppix]# sudo password
sudo: password: command not found
root@ttyp1[knoppix]# sudo password knoppix
sudo: password: command not found
root@ttyp1[knoppix]#
The command is 'passwd' not 'password'.
Quote:
with a floppy disk in the drive
knoppix@ttyp2[knoppix]$ su
root@ttyp2[knoppix]# ls /mnt/auto/floppy
ls: /mnt/auto/floppy: No such file or directory
root@ttyp2[knoppix]#
There may be something error here, that should work with a disk in the drive.
Quote:
knoppix@ttyp3[knoppix]$ ls /ect
ls: /ect: No such file or directory
......
knoppix@ttyp0[knoppix]$ cat /ect/fstab
cat: /ect/fstab: No such file or directory
knoppix@ttyp0[knoppix]$ su
root@ttyp0[knoppix]# cat /ect/fstab
cat: /ect/fstab: No such file or directory
root@ttyp0[knoppix]#
The directory is '/etc' not 'ect'.
Quote:
with a router and cable modem connected but coax cable to ISP removed I got this output.
knoppix@ttyp0[knoppix]$ ping -c 5 216.239.57.99
PING 216.239.57.99 (216.239.57.99): 56 data bytes
--- 216.239.57.99 ping statistics ---
5 packets transmitted, 0 packets received, 100% packet loss
knoppix@ttyp0[knoppix]$
This is as expected. You cannot ping google if you are not on line.
again I am stressing that there is no ability to mnt/floopy
To the list;
This is exactly what the original post brought up.Got ony ideas?
With a floppy in the floppy drive this was the output.
knoppix@ttyp0[knoppix]$ mnt /dev/fd0
bash: mnt: command not found
knoppix@ttyp0[knoppix]$ mount /dev/fd0
/dev/fd0: Input/output error
mount: mount point /mnt/auto/floppy does not exist
knoppix@ttyp0[knoppix]$ su
root@ttyp0[knoppix]# mnt /dev/floppy
bash: mnt: command not found
root@ttyp0[knoppix]# mount /dev/floppy
mount: can't find /dev/floppy in /etc/fstab or /etc/mtab
root@ttyp0[knoppix]# mount /dev/fd0
/dev/fd0: Input/output error
mount: mount point /mnt/auto/floppy does not exist
root@ttyp0[knoppix]# mount /dev/auto/floppy
mount: can't find /dev/auto/floppy in /etc/fstab or /etc/mtab
root@ttyp0[knoppix]# mnt /dev/auto/fd0
bash: mnt: command not found
root@ttyp0[knoppix]#
thanks again
finder
more about the inability to mount floppy
To the list;
This is exactly what the original post brought up.Got ony ideas?
With a floppy in the floppy drive this was the output.
knoppix@ttyp0[knoppix]$ mnt /dev/fd0
bash: mnt: command not found
knoppix@ttyp0[knoppix]$ mount /dev/fd0
/dev/fd0: Input/output error
mount: mount point /mnt/auto/floppy does not exist
knoppix@ttyp0[knoppix]$ su
root@ttyp0[knoppix]# mnt /dev/floppy
bash: mnt: command not found
root@ttyp0[knoppix]# mount /dev/floppy
mount: can't find /dev/floppy in /etc/fstab or /etc/mtab
root@ttyp0[knoppix]# mount /dev/fd0
/dev/fd0: Input/output error
mount: mount point /mnt/auto/floppy does not exist
root@ttyp0[knoppix]# mount /dev/auto/floppy
mount: can't find /dev/auto/floppy in /etc/fstab or /etc/mtab
root@ttyp0[knoppix]# mnt /dev/auto/fd0
bash: mnt: command not found
root@ttyp0[knoppix]#
thanks again
finder
Re: more about the inability to mount floppy
Quote:
knoppix@ttyp0[knoppix]$ mount /dev/fd0
/dev/fd0: Input/output error
mount: mount point /mnt/auto/floppy does not exist
That should work. So, since it appears from fstab that konoppix is finding your floppy drive, lets try without the automounter & lets specify a mount point we know exists.
First 'sudo /etc/init.d/autofs stop' to shut down the automounter.
Now check that there is a directory /mnt/test
ls /mnt
You should get a list of the subdirectories in directory /mnt and one of them should be 'test'
Now 'sudo mount /dev/fd0 /mnt/test'
If you don't get any error message do:
ls /mnt/test
and you should get a read from your floppy.
this is some of what I found in the /etc/services/ files
To the list;
Sorry about the length of these messages but what about this information?
any ideas?
let me know
finder
This is a copy of what was in my file:/etc/security/accessconf file.
Is the lower information correct?
# Login access control table.
#
# When someone logs in, the table is scanned for the first entry that
# matches the (user, host) combination, or, in case of non-networked
# logins, the first entry that matches the (user, tty) combination. The
# permissions field of that table entry determines whether the login will
# be accepted or refused.
#
# Format of the login access control table is three fields separated by a
# ":" character:
#
# [Note, if you supply a 'fieldsep=|' argument to the pam_access.so
# module, you can change the field separation character to be
# '|'. This is useful for configurations where you are trying to use
# pam_access with X applications that provide PAM_TTY values that are
# the display variable like "host:0".]
#
# permission : users : origins
#
# The first field should be a "+" (access granted) or "-" (access denied)
# character.
#
# The second field should be a list of one or more login names, group
# names, or ALL (always matches). A pattern of the form user@host is
# matched when the login name matches the "user" part, and when the
# "host" part matches the local machine name.
#
# The third field should be a list of one or more tty names (for
# non-networked logins), host names, domain names (begin with "."), host
# addresses, internet network numbers (end with "."), ALL (always
# matches) or LOCAL (matches any string that does not contain a "."
# character).
#
# If you run NIS you can use @netgroupname in host or user patterns; this
# even works for @usergroup@@hostgroup patterns. Weird.
#
# The EXCEPT operator makes it possible to write very compact rules.
#
# The group file is searched only when a name does not match that of the
# logged-in user. Both the user's primary group is matched, as well as
# groups in which users are explicitly listed.
#
# TTY NAMES: Must be in the form returned by ttyname(3) less the initial
# "/dev/" (e.g. tty1 or vc/1)
#
################################################## ############################
#
# Disallow non-root logins on tty1
#
#-:ALL EXCEPT root:tty1
#
# Disallow console logins to all but a few accounts.
#
#-:ALL EXCEPT wheel shutdown sync:LOCAL
#
# Disallow non-local logins to privileged accounts (group wheel).
#
#-:wheel:ALL EXCEPT LOCAL .win.tue.nl
#
# Some accounts are not allowed to login from anywhere:
#
#-:wsbscaro wsbsecr wsbspac wsbsym wscosor wstaiwde:ALL
#
# All other accounts are allowed to login from anywhere.
#
This was found at the end of the /etc/services/groups conf file.
Is is possible that the mnt/dev/fd0 could have been placed into a group and made off-limits
to the users? Is it possible to make these changes remotely in Knoppix when you can't have a
secure root or ssh or telnet services can be opened and run remotely?
#
#
# Here is a simple example: running 'xsh' on tty* (any ttyXXX device),
# the user 'us' is given access to the floppy (through membership of
# the floppy group)
#
#xsh;tty*&!ttyp*;us;Al0000-2400;floppy
# another example: running 'xsh' on tty* (any ttyXXX device),
# the user 'sword' is given access to games (through membership of
# the sound and play group) after work hours. (The games group owns
# high-score files and so on, so don't ever give users access to it.)
#
#xsh; tty* ;sword;!Wk0900-1800;sound, play
#xsh; tty* ;*;Al0900-1800;floppy
#
# End of group.conf file
#
This was from the end of the /etc/services/time file.
This is telling me that a time lock out can occur from root via a ssh or
telnet connection. How can this be prevented?
#
# Here is a simple example: running blank on tty* (any ttyXXX device),
# the users 'you' and 'me' are denied service all of the time
#
#blank;tty* & !ttyp*;you|me;!Al0000-2400
# Another silly example, user 'root' is denied xsh access
# from pseudo terminals at the weekend and on mondays.
#xsh;ttyp*;root;!WdMo0000-2400
#
# End of example file.
This was the only line in my /etc/services/fileshare.conf file
RESTRICT=no
*************************************
security apps down, kernel hacked/ this is the test output
To the list;
This was the output from your suggestion.
knoppix@ttyp0[knoppix]$ sudo mount /dev/fd0 /mnt/test
/dev/fd0: Input/output error
mount: you must specify the filesystem type
knoppix@ttyp0[knoppix]$
I very frequently reboot the machine and I cut the current/power to the machine but somehow this doesn't keep the hacker out. I somehow think that in the cron files is the ability to send a fax with a ip and with that the hacker knows where to go. The confusing part is that you do not start over anew when you reboot. There is files that remain altered. Somehow things don't function properrly and security is all disabled.
My nessus log has nothing in it for Novenmber. It never reports anything. I go to Control Center/system administration/Linux Kernel and get the following error message.
Sorry
The kernel configuration could not be read due to the following error:
cannot open /usr/src/linux/arch//config.in for reading.
Either your kernel sources contain invalid configuration rules or you just found a bug in the KDE Kernel Configurator.
any ideas?
finder
this is the other suggestion
knoppix@ttyp0[knoppix]$ mount -t vfat /dev/fd0 /mnt/floppy
mount: only root can do that
knoppix@ttyp0[knoppix]$
knoppix@ttyp0[knoppix]$ su
root@ttyp0[knoppix]# mount -t vfat /dev/fd0 /mnt/floppy
mount: mount point /mnt/floppy is a symbolic link to nowhere
root@ttyp0[knoppix]#
root@ttyp0[knoppix]#
any ideas?
finder
Re: this is the other suggestion
Quote:
Originally Posted by finder
knoppix@ttyp0[knoppix]$ mount -t vfat /dev/fd0 /mnt/floppy
mount: only root can do that
knoppix@ttyp0[knoppix]$
knoppix@ttyp0[knoppix]$ su
root@ttyp0[knoppix]# mount -t vfat /dev/fd0 /mnt/floppy
mount: mount point /mnt/floppy is a symbolic link to nowhere
root@ttyp0[knoppix]#
root@ttyp0[knoppix]#
any ideas?
finder
/mnt/floppy is probably a link to /mnt/auto/floppy which doesn't exist since it is created by the automounter
try mounting on a mount point (directory) known to exist.
if you are root:
mount -t vfat /dev/fd0 /mnt/test
or if you are not root:
sudo mount -t vfat /dev/fd0 /mnt/test