Originally posted by: dphantom
Now if I can just figure out the root password.....
I am using Telnet 😱 Cause I do remote Logins.Originally posted by: nweaver
eh...you have telnet enabled, your box is due for ownage soon....
welcome to 2006, telnet, rlogin, etc are ALL DEAD...use SSH, turn off all unneeded services, change standard port for SSH, use strong passwords,
I personally lock down SSH so that it requires keys to login, change it's port, chroot any services I can, lock down WHO can connect to that ssh port (what IP's) if it's work related, and use something with a sane package managment system (Deb stable is my preferred) to keep up to date on security.
Originally posted by: Mir96TA
Originally posted by: dphantom
Now if I can just figure out the root password.....
Naaa I am not going to tell ya THAT.😀
I am using Telnet 😱 Cause I do remote Logins.Originally posted by: nweaver
eh...you have telnet enabled, your box is due for ownage soon....
welcome to 2006, telnet, rlogin, etc are ALL DEAD...use SSH, turn off all unneeded services, change standard port for SSH, use strong passwords,
I personally lock down SSH so that it requires keys to login, change it's port, chroot any services I can, lock down WHO can connect to that ssh port (what IP's) if it's work related, and use something with a sane package managment system (Deb stable is my preferred) to keep up to date on security.
See the way I see, only way I can learn is install the Box then Break it then Fix it 🙂
Originally posted by: Mir96TA
Originally posted by: dphantom
Now if I can just figure out the root password.....
Naaa I am not going to tell ya THAT.😀
I am using Telnet 😱 Cause I do remote Logins.Originally posted by: nweaver
eh...you have telnet enabled, your box is due for ownage soon....
welcome to 2006, telnet, rlogin, etc are ALL DEAD...use SSH, turn off all unneeded services, change standard port for SSH, use strong passwords,
I personally lock down SSH so that it requires keys to login, change it's port, chroot any services I can, lock down WHO can connect to that ssh port (what IP's) if it's work related, and use something with a sane package managment system (Deb stable is my preferred) to keep up to date on security.
See the way I see, only way I can learn is install the Box then Break it then Fix it 🙂
Originally posted by: Mir96TA
Originally posted by: dphantom
Now if I can just figure out the root password.....
Naaa I am not going to tell ya THAT.😀
I am using Telnet 😱 Cause I do remote Logins.Originally posted by: nweaver
eh...you have telnet enabled, your box is due for ownage soon....
welcome to 2006, telnet, rlogin, etc are ALL DEAD...use SSH, turn off all unneeded services, change standard port for SSH, use strong passwords,
I personally lock down SSH so that it requires keys to login, change it's port, chroot any services I can, lock down WHO can connect to that ssh port (what IP's) if it's work related, and use something with a sane package managment system (Deb stable is my preferred) to keep up to date on security.
See the way I see, only way I can learn is install the Box then Break it then Fix it 🙂
Originally posted by: dphantom
Originally posted by: Mir96TA
Originally posted by: dphantom
Now if I can just figure out the root password.....
Naaa I am not going to tell ya THAT.😀
I am using Telnet 😱 Cause I do remote Logins.Originally posted by: nweaver
eh...you have telnet enabled, your box is due for ownage soon....
welcome to 2006, telnet, rlogin, etc are ALL DEAD...use SSH, turn off all unneeded services, change standard port for SSH, use strong passwords,
I personally lock down SSH so that it requires keys to login, change it's port, chroot any services I can, lock down WHO can connect to that ssh port (what IP's) if it's work related, and use something with a sane package managment system (Deb stable is my preferred) to keep up to date on security.
See the way I see, only way I can learn is install the Box then Break it then Fix it 🙂
Use SSH then. Listen to nweaver...learn. You might keep your box longer.
Originally posted by: Mir96TA
This is my IP 24.36.239.86 (Telnet)
How I can test it is Good or Not
I am just playing with the Box and learning
You need to disable Incoming ICMP Echo requests (Pings). Also disable UDP/TCP/ ping requests.
If you have ICMP enabled you are going to get DoS attacked.
I want to get owned! Big time
Take over the Box....
LOL. I was hoping you'd go first.Originally posted by: Nothinman
I doubt that'll happen from anyone here, there's no way you can prove that's really your IP.I want to get owned! Big time
Take over the Box....
Thanks Good People like us
Originally posted by: Nothinman
Thanks Good People like us
I think it's more that people just tend to forget that you're there =)
Originally posted by: Mir96TA
I want to get owned! Big time
Take over the Box......
On Worst Case All I have to de Rebuild
That is the Goal.
All I want in Retuen; If you were able to get in
Please tell me How you did! and If you can Create Dir "Dummy" if there is one already
Create DummyX X=1 or numbers.......
Box just a Simple Box
I got no Data which I care....... So go ahead do it what ever you Can 🙂
Then tell meOriginally posted by: InlineFive
Originally posted by: Mir96TA
I want to get owned! Big time
Take over the Box......
On Worst Case All I have to de Rebuild
That is the Goal.
All I want in Retuen; If you were able to get in
Please tell me How you did! and If you can Create Dir "Dummy" if there is one already
Create DummyX X=1 or numbers.......
Box just a Simple Box
I got no Data which I care....... So go ahead do it what ever you Can 🙂
Erm, why do you need us to intentionally break it (while possibly violating a few laws) when we can just tell you what is wrong?
Originally posted by: Bradtechonline
Well, I just ate up all your bandwidth because you won't disable incoming echo request. Your ping times are in the 1,000's right now. I got enough bandwidth to eat up almost all of yours.
Do yourself a favor, and block it.
Originally posted by: n0cmonkey
Originally posted by: Bradtechonline
Well, I just ate up all your bandwidth because you won't disable incoming echo request. Your ping times are in the 1,000's right now. I got enough bandwidth to eat up almost all of yours.
Do yourself a favor, and block it.
First, blocking ICMP requests doesn't solve the bandwidth issue. If the data has made it to the firewall it's already in the pipe. If it's in the pipe, the pipe can be saturated.
Second, ICMP is important and shouldn't be blocked.
What does blocking icmp really do for you? It definitely isn't anything security related...