[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Followup: [cobalt-users] Qube Hacked



Well I am back up and running now - Still tweaking things. But thought I would post a couple things I found out.

My qube is an older Qube3 Business Ed. Came with one 20GB drive and I later added a 60GB.

I was not successful in loading either of the OSRCD OS 6.4 CDs. Business or Pro- THey both hung installing a RPM (different one in all cases) and never came back. They did format and partition the 60GB hard drive.

I finally got the Business edition ml OSRCD and that loaded. I then went to the Sun Cobalt patch page and loaded all 47 patches (or attempted to - a few do not load on this config) Had a bit of a hickup when I screwed up while loading number 27 and had to start over from scratch. (I filled up the root directory trying to do two things at once - dumb dumb).

After getting it all patched I formated the 60GB drive and moved /home/users there and changed the mount point.

NOTE: A real gotcha: SQUID in it's default patched config opens up huge security holes. (The reason I got into this mess in the first place) So I do not enable it. HOWEVER for some reason it starts up anyway until in the GUI you first enable it and then disable it. Somewhere in the scripts there is an incorrectly set toggle switch. Also I had disabled it earlier and it got enabled again - I think through a patch but I cannot trace it. I now run a script to look for squid as well as the chkrootkit.

One other thing I did which made things easier - I downloaded all the patches and as I saved them I prepended a number to the filename (ie: 01-Qube3......, 02-Qube3.... ) That made installing easier but I have got to build my own OSRCD!

Cheers ALL!
Linda

Linda Knapp wrote:
One more thing - If I do start with the OS ProED 6.4 CD where can I find the list of updates I need (In the correct order) Looks like the one on the Sun site is all the patches.

BTW - My 2 disks are a 20GB (the original disk ) and a 60GB.

Thanks!
Linda

Linda Knapp wrote:

Well it finally happened - I think that my Qube3 has a rootkit installed so I am in the process of getting everything together to restore it.

One big question - this is an older qube3 which came with one hard drive. I added a hard drive to it and put the home directories over there a while back. On reinstall I would like to start with the 6.4 OS CD can I go ahead and install the pro version which includes RAID?

Originally I had either Qube3 multilanguage Standard or Business version. I of course cannot find that CD right now so am downloading a new image. Do I need to start with the Multilanguage Business version?

Any other pointers before I do this? It is a pretty clean system just used for email and a couple websites.

Linda


_____________________________________
cobalt-users mailing list
cobalt-users@xxxxxxxxxxxxxxx
To subscribe/unsubscribe, or to SEARCH THE ARCHIVES, go to:
http://list.cobalt.com/mailman/listinfo/cobalt-users



_____________________________________
cobalt-users mailing list
cobalt-users@xxxxxxxxxxxxxxx
To subscribe/unsubscribe, or to SEARCH THE ARCHIVES, go to:
http://list.cobalt.com/mailman/listinfo/cobalt-users