6 ms·
What is the best approach to guarding against crap like this on Linux, Ubuntu specifically?
by macmac 9y ago
What is the best approach to guarding against crap like this on Linux, Ubuntu specifically?
- black_puppydog 9y agowell, as the article states, this attack needs elevated rights on your machine anyway. so to install that, you need to be pwned in the first place. and (also stated) you better hope that all admins of all websites/services you use take care about this, too, since they're the real juicy targets...
- jaimex2 9y agoDon't run random scripts basically, always check their content. Specially if they require root.
- astrodust 9y agoWelp, there goes Rubygems and NPM global modules.
- zurn 9y agoAlways wall off your dev/admin machine and all the credentials therein. Sandbox NPM type things using a VM or at least a non-root container.
- chocolateboy 9y agoNeither requires root: * https://github.com/creationix/nvm https://github.com/creationix/nvm * http://kazhack.org/?post/2014/12/11/npm-install-g-without-sudo http://kazhack.org/?post/2014/12/11/npm-install-g-without-su... * http://kazhack.org/?post/2014/12/12/pip-gem-install-without-sudo http://kazhack.org/?post/2014/12/12/pip-gem-install-without-...
- astrodust 9y agoYou can do it without root if you take precautions, but the default is to use root.
- chocolateboy 9y agoDepends on the system. The default on Arch Linux is local gem installs: $ cat /etc/gemrc # --user-install is used to install to $HOME/.gem/ by default since we want to separate # pacman installed gems and gem installed gems gem: --user-install
- astrodust 9y agoThat's a nice touch and some good work on the part of the package maintainer. Most (Ubuntu, RedHat, etc.) do not, they just expect you to sudo everything.
- deleted 9y ago[deleted]
- Thaxll 9y agoIf you don't use Iptables you can blacklist the modules from loading at boot. https://help.ubuntu.com/community/Loadable_Modules https://help.ubuntu.com/community/Loadable_Modules
- ComodoHacker 9y agoOTOH, not using iptables leaves you vulnerable to many other crap.
- safeharbourio 9y agothere is ufw and firewalld.
- a3n 9y agoDisclaimer: I'm a casual Linux user, not an experienced system administrator. My understanding is that ufw uses iptables under the hood. I use ufw, yet my laptop (casual user) has iptables; don't know whether it was installed as a result of installing ufw, or if it's there by default. Regardless of using iptables or ufw, these are both for manipulating the lower level kernel network firewall. And the article shows using iptables to load an nf kernel module. (I think) it's the module that's important, and iptables is just the convenience function to get it done. Anyone who has root access could easily install and uninstall iptables, or use some other method of module installation. I think.
- danieldk 9y agoAll these tools just manage iptables or nftables rules.
- warbiscuit 9y agoNot to mention shorewall, which IMO provides a really nice abstraction over iptables, that fits 90% of the needs out there.
- danieldk 9y agoIn principle, secure boot plus signed kernel modules: https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/System_Administrators_Guide/sect-signing-kernel-modules-for-secure-boot.html https://access.redhat.com/documentation/en-US/Red_Hat_Enterp... Though, I am not sure how vulnerable the key infrastructure is to the CIA.
- scriptkiddy 9y agoOn Ubuntu specifically, ensure that you are only installing packages from Cannonical's repositories or VERY trusted PPAs.