Page 1 of 2 12 LastLast
Results 1 to 10 of 12

Thread: Knoppix & Security : Ongoing Issue

  1. #1
    Junior Member
    Join Date
    May 2003
    Posts
    2

    Knoppix & Security : Ongoing Issue

    Hello All,

    First of all, let me thank all of you who have contributed your time and effort into this project. Personally, I am one of the few who must say that this is worth all the sweat and hours. I would like to thank everyone who contributed for providing the public with a beautiful method to bring Linux onto the top of the ladder. You deserve more than this little paragraph, thank you.

    Now, I must be frank with you and I will be. I am a beginner at Linux, in terms of that compared to my knowledge with DOS/Windows, I practically know very little about Linux. Yes, ofcourse I know the basic commands and how to get around, I have successfully used RedHat/Mandrake/Slackware before, but because of some hardware incompabilities (and other issues), I did not ever keep my eyes on any of the Linux distributions for too long.

    Knoppix has changed that, and I thank you. Once booted into the system, I was very surprized with the ease it found most of my 'incompatible' hardware, the wide variety of software it presented (although I'm pretty sure, alot of packages could be removed, alot could be added), and altogether the idea of having a Live-CD Linux running gave me an intellectual orgasm

    Nevertheless, to cut the chase, I am very concerned with the security issue of Knoppix. I am well aware that Linux outperforms Windows platform, but the fact that I am not familiar with the whole system (just yet) gives me the feeling of unease while I am physically connected to the net (yes, it is called physical, wires still are physical).

    Take a look at this thread :

    http://www.knoppix.net/forum/viewtopic.php?t=2234

    It offered basic opinions on the 'security' of Knoppix. Very well, but I hope you dont mind if I be the first to ask a few more questions and clarify some information myself.

    Knoppix Security :

    1) Linux itself is somewhat a better security 'tool' than Windows, but most of the times, thats the case if one knows their facts and maintains the operating system.

    2) Knoppix has a very big advantage, its booted off a CD (it cant do Live writing onto the CD), and loads itself into the memory (reboot, and everything unsaved is gone, literally)

    3) Knoppix (hopefully) is pre-installed with updated software patches, fixes and packs as a whole. It includes (hopefully) the most secure configurations available.

    Now, onto a few (or not) of my questions.

    1) Compared to other distributions/setups/configurations, the default Knoppix (3.2 at this time), is it secure in terms of that its patched, and config'ed to run without any major hassles, protecting the machine against beginner and intermediate attacks / hacker attempts from the net ?

    2) Although Knoppix is a Live-CD, if one has a Hard Drive connected and mounted, whoever gains access to the system can ultimately access the Hard Drive to and perform malicious tasks which can result in damage of the files.
    Specific question : NTFS is the Standard format system for some of the Windows platforms, and although it is recognized for reading by Linux, the writing algorithms/code is very shaky, thus is not enabled by default. If one (such as myself) has NTFS drives mounted (for data access) in Knoppix, is there a less of a chance of an intruder to break into the HD and attempt to destroy data, since NTFS is 'read-only' ? What are the tools that allow Knoppix to write data in NTFS format and can they be disabled ? Any other suggestions ?

    3) I have various tools running on my Windows platform. Now, surely the first thing to do is to set up a firewall on Linux. Can anyone direct me to the most beginner / quickest way for me to setup a basic firewall until the time I can read up and do a detailed configuration ? I have attempted to lookup information on this, and found two packages that were a bit advanced for me, thus I came here.

    4) Generally, please present your worst security concerns with Knoppix and Linux. Please refrain from overstatements such as that any working box is vulnerable, for this is a given fact. Lets keep it to the level of the vulnerability and not whether it is or not. Also, please explain what issues are there with Knoppix separately from other Linuxes, with Linux as a whole. Feel free to get as technical as you can, but without any specific details (such as a denial of service of some irrelevant protocol)

    Thank you very much for the attention. I hope that everyone can input in this, for this thread might be read by many newcomers, since Linux these days literally stands for 'security, stability (and hopefully later) comfort (?)'. Please refrain from useless posts. I apologize for any misunderstandings, overstatements or improper use of language / terms. Please no flame but I am eager to read your detailed opinion and views on the subject.

  2. #2
    Senior Member registered user
    Join Date
    Mar 2003
    Posts
    872
    I think your questions boil down to 2 :

    1. Boot KNOPPIX to play around the local HD(and its data). This is unfortunately true and it should not be a concern as allowing someone to boot something from floppy/cd already opens the door, this is not just a KNOPPIX issue. There are some single floppy rescue linux image on the internet which in the proper(inproper) hand, can do anything on a harddisk.

    2. attack from the the net. This should not be a problem for KNOPPIX as it doesn't start any server so all TCP port are closed(the equivalent of behind a firewall).

    So KNOPPIX by default is safe. The biggest security issue with it is it has an unlocked root so anyone with enough linux knowledge can use it to gain access to whatever machine and start servers which can invite trouble. If you want to distribute it in a typical environment like school, I would advice you to remaster it to lock the root access(through password). If you use it at home, the biggest security concern is the person in front of the machine(you have the choice to wipe out the harddisk or start servers, or not), not KNOPPIX

  3. #3
    Senior Member registered user
    Join Date
    Feb 2003
    Location
    Nova Scotia, Canada
    Posts
    2,479
    For an easy firewall apt-get install guarddog nice graphic interface. For just plain text file Arno's firewall works great simple instructions and easy NAT if you want to share the internet.

  4. #4
    Senior Member registered user
    Join Date
    Nov 2002
    Location
    Auckland, New Zealand
    Posts
    818
    Quote Originally Posted by Stephen
    For an easy firewall apt-get install guarddog nice graphic interface. For just plain text file Arno's firewall works great simple instructions and easy NAT if you want to share the internet.
    I like shorewall. It's reasonably easy to set up, and very powerful.

    John -
    Regarding you question 1 - pretty much yes. It doesn't run any services, and usually includes the latest secruity updates. There was a stage when it didn't include the latest KDE update, but that was becasue there wasn't a debian package for it.

    q 2 - it doesn't matter what filesystem is on the disk or weather it is mounthed or not, becasue if they had root they have access to the raw disk and could di anything e.g. repartition it.

    q 3 - You don't need a firewall unless you are running services on your external interface and don't want them accable publicly.
    You can see what services are running by doing a
    nmap 192.168.1.1 - where that ip address is your ethernet address

    q 4 - Running off a cd, I couldn't hack knoppix remotely afaik. I guess the biggest concern with running off the cd, is that if someone gains any access, they gain root access.

    Hmm. I have an idea - How bout a cheatcode - rootpassword

    So boot up knoppix with rootpassword=MyPassword and instead of the sudo, you have a root password, that is only used for that session, this way, if someone does get user level access, they don't have root access.

    And John Doe, Please change the email address in your profile or your account will be deleted.

  5. #5
    Junior Member
    Join Date
    May 2003
    Posts
    2
    Hello All and thank you for your input,

    I have read your answers and came down with the following ideas:

    I) As of the moment, Knoppix is patched and somewhat secure to the known attacks/exploits from the net. Thus as long as one keeps the physical access to the computer safe/restricted, the outside (to the internet) can be considered to be safe.

    2) Firewall is needed only if one runs a service or keeps TCP port open.

    3) The largest problem with Knoppix is the root access (which by default has no password ? I have tried 'su' and gained root level without any password). I very much appreciate the 'rootpassword' parameter at the bootup, it probably saved me hours of work of figuring out how I would make sure that the root password would be something of my choice.

    Thank you, I will look into this tonight and update the thread with any additional questions that may arise. If anyone else who is reading this thread wishes to act keypoints about Knoppix's default security and security issues that may arise with fresh bootup of Knoppix on any random machine, please dont be shy and contribute.

    PS: The email is changed temporarily.

  6. #6
    Senior Member registered user
    Join Date
    Nov 2002
    Posts
    1,353
    Another nice firewall is Firestarter. I'm currently using 0.9.1 (in unstable). It has to be the easiest firewall available to linux, but it's still powerfull. It also lets you easily set up internet connection sharing if you have two nics.

    The only downside is that it is a GUI only program. That makes it fine in the case of the laptop I'm using right now, but I'd like to explore some CLI firewalls. Shorewall looks interteresting. Maybe I'll give that a try sometime.

  7. #7
    Senior Member registered user
    Join Date
    Mar 2003
    Posts
    298
    Quote Originally Posted by eadz
    Hmm. I have an idea - How bout a cheatcode - rootpassword

    So boot up knoppix with rootpassword=MyPassword and instead of the sudo, you have a root password, that is only used for that session, this way, if someone does get user level access, they don't have root access.
    Hehe, you probably want to change that to "rootpassword", and then *interactively* ask a new root password while booting. Unless you like entering a password in plaintext...

  8. #8
    Senior Member registered user
    Join Date
    Nov 2002
    Location
    USA, IL
    Posts
    1,041
    --Good point, as I believe the kernel parms are accessible via either dmesg or other means...

    --Seriously, thanks for all the firewall tips. I'll be investigating them and passing them on to a friend.

    Quote Originally Posted by Henk Poley
    Quote Originally Posted by eadz
    Hmm. I have an idea - How bout a cheatcode - rootpassword

    So boot up knoppix with rootpassword=MyPassword and instead of the sudo, you have a root password, that is only used for that session, this way, if someone does get user level access, they don't have root access.
    Hehe, you probably want to change that to "rootpassword", and then *interactively* ask a new root password while booting. Unless you like entering a password in plaintext...

  9. #9
    Senior Member registered user
    Join Date
    Nov 2002
    Posts
    1,353
    Quote Originally Posted by Henk Poley
    Hehe, you probably want to change that to "rootpassword", and then *interactively* ask a new root password while booting. Unless you like entering a password in plaintext...
    This will enter your root password in plain text? Yikes. Thanks.

  10. #10
    Senior Member registered user
    Join Date
    Mar 2003
    Location
    colorado springs, colorado
    Posts
    1,933
    Your concerns John Doe are why I choose to run a Linux router. If you want cute and fuzzy blinky blinky lights- get netgear or dlink or whomevers toothpick and duct-tape fortress and wait until some software engineering geeks decide it's time for a firmware update because bloody hell- somebody is causing stack overflows on their poorly tested products again. If they had safety inspections for routers like they do for most consumer products then those companies would be out of business.

    If you want real security build your own router. Boot the OS from a removable disc, either a floppy or cdrom. If your router OS is installed on a hard drive then it can be written to- period.

    As has already been pointed out, anything on a ramdisk will never survive a reboot. Assuming you don't leave the floppy in the drive or turn the write protection on you're in good shape.

    Security is a matter of what it takes to make you feel secure. How do you fare in a port scan- a thoughrough port scan, not just the most commonly used ports from a site that wants to sell you wimpdoze security fixes. If you run a windows machine I would be extremely nervous about security- it has more holes than swiss cheese.

    Think about this: I firmly beleive that it is not an option to be secure but rather, it is your responsibility. Afterall, what thrill is there in creating viri? You can't take credit for it so you need to hear about how many machines it affected. What if everyone was doing all that they could to be secure? Surely then hackers would lose much of their motivation and satisfaction.

    I almost never install anything with a cute GUI based installer-why? They can't be trusted. If it's not open source it isn't on my box. If you're a windoze user you already know more than you ever wanted to about freeware apps and the extra *cough* features they sometimes bring along.

    Build a router, make it small, make it cool looking- install Linux to your network machines, put each users /home directory on a seperate partition, don't get lazy with permissions and you will likely never reinstall an OS again.

    Well ok that's not entirely true. You see...............Linux in and of itself is highy addictive and you will soon find yourself saying "so many distro's so little time".

Page 1 of 2 12 LastLast

Similar Threads

  1. Security ISSUE for netowrk ???
    By prelude in forum Networking
    Replies: 7
    Last Post: 09-15-2004, 04:17 AM
  2. knoppix security
    By lordb in forum Hdd Install / Debian / Apt
    Replies: 1
    Last Post: 05-02-2004, 06:43 AM
  3. SECURITY ISSUE
    By alxdotnet in forum Hdd Install / Debian / Apt
    Replies: 0
    Last Post: 02-12-2004, 05:57 PM
  4. Knoppix Security
    By Bd84 in forum General Support
    Replies: 12
    Last Post: 05-27-2003, 04:16 PM
  5. Knoppix and security
    By WT in forum General Support
    Replies: 1
    Last Post: 12-31-2002, 09:21 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  


GIGABYTE A520M DS3H AC AMD AM4 Motherboard mATX picture

GIGABYTE A520M DS3H AC AMD AM4 Motherboard mATX

$59.99



GIGABYTE Z790 AORUS ELITE AX LGA 1700 Intel Z790 ATX Motherboard with DDR5 picture

GIGABYTE Z790 AORUS ELITE AX LGA 1700 Intel Z790 ATX Motherboard with DDR5

$189.99



Intel H310 LGA1151 8-9th Gen DDR4 M.2 NVMe mATX Motherboard IO Shield Battery picture

Intel H310 LGA1151 8-9th Gen DDR4 M.2 NVMe mATX Motherboard IO Shield Battery

$54.99



ASUS PRIME Z490-V Motherboard Intel Z490 10th gen DDR4 LGA 1200 ATX w/ IO Shield picture

ASUS PRIME Z490-V Motherboard Intel Z490 10th gen DDR4 LGA 1200 ATX w/ IO Shield

$84.99



GIGABYTE B365 HD3 LGA1151 Intel 9th Gen motherboard picture

GIGABYTE B365 HD3 LGA1151 Intel 9th Gen motherboard

$59.99



⁠Intel H81 Motherboard M.2 NVMe LGA 1150 mATX w/ IO Shield (Random Slot Color)⁠ picture

⁠Intel H81 Motherboard M.2 NVMe LGA 1150 mATX w/ IO Shield (Random Slot Color)⁠

$29.90



ASUS PRIME B360M-C MicroATX Intel LGA1151 DDR4 HDMI VGA USB RJ-45 Audio picture

ASUS PRIME B360M-C MicroATX Intel LGA1151 DDR4 HDMI VGA USB RJ-45 Audio

$34.99



ASUS PRIME Z370-A II LGA 1151 Intel Z370 DDR4 DIMM USB3.1 DVI  ATX RGB picture

ASUS PRIME Z370-A II LGA 1151 Intel Z370 DDR4 DIMM USB3.1 DVI ATX RGB

$69.99



Dell XPS 8940 Desktop Motherboard Intel H470 LGA1200 DDR4 K3CM7 KV3RP 427JK picture

Dell XPS 8940 Desktop Motherboard Intel H470 LGA1200 DDR4 K3CM7 KV3RP 427JK

$154.99



ASRock Z370 Pro4 LGA 1151 Z370 HDMI USB 3.1 2 Ultra M.2 DDR4 ATX Motherboard picture

ASRock Z370 Pro4 LGA 1151 Z370 HDMI USB 3.1 2 Ultra M.2 DDR4 ATX Motherboard

$75.00