[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[no subject]



Again, on a not-so-important systems, knock yourself out.



On 5/18/05, ChangingLINKS.com &lt;<a  rel="nofollow" href="http://ChangingLINKS.com";>http://ChangingLINKS.com</a>&gt; &lt;
groups at changinglinks.com&gt; wrote:
&gt; 
&gt; On Tuesday May 17 2005 18:02, Geoffrey wrote:
&gt; &gt; &gt; CHALLENGE:
&gt; &gt; &gt; 1. If no one can down/infect/harm my system for more than 20 minutes
&gt; &gt; &gt; TOTAL - you fix (or have fixed) the 6 problems that I posted (and give 
&gt; me
&gt; &gt; &gt; exact directions on how to apply the fixes myself.)
&gt; &gt;
&gt; &gt; You're on.
&gt; 
&gt; . At 1800 (6PM) on Sunday 05-22-05 the challenge will begin.
&gt; . I will setup my box like so: Internet -&gt; broadband cable modem -&gt; box
&gt; . I will drop all firewall rules
&gt; . Geoffrey can confirm by phone that he has no problems reaching /
&gt; . I will leave the system open for 30 minutes
&gt; . During this time anyone on the ALE list can hack at my DAILY USE box
&gt; . At 1830 (6:30PM) I will restore the entire computer within 10 minutes.
&gt; . Finally, I will post the procedure for restoring the system as proof.
&gt; 
&gt; Overview of the system:
&gt; This challenge is similar to Bob Toxen's &quot;expert hacker&quot; challenge. Like 
&gt; him,
&gt; I will give away the IP address.
&gt; 
&gt; Unlike him, though, I will go much further:
&gt; I will give everyone the root password
&gt; I will be running as root the entire time
&gt; I will drop all firewalls and typical security that I run
&gt; I will NOT have a &quot;hot spare&quot; - or more than 1 hard drive in the box
&gt; I will run a server including Apache, PHP
&gt; (Bob said it was very insecure awhile back),
&gt; MySQL, Perl, sshd (if I remember to start it)
&gt; I will NOT add or remove hardware during or immediately after the 
&gt; challenge.
&gt; Moreover, I will do my best to verify that ALL of you can reach root.
&gt; 
&gt; For this challenge, I will be removing personal data from the system. My 
&gt; worry
&gt; is not to protect it from loss, but since I will be giving FULL access to 
&gt; the
&gt; entire box - and want to keep the private data private. Outside of the
&gt; missing data, the lack of firewalls, and the direct connection to the 
&gt; 'Net,
&gt; you will have direct access to the setup that I run everyday as root. I 
&gt; can't
&gt; think of anything else that will aid my defeat. My point is that I will 
&gt; not
&gt; try to hinder the hacking - I will let the box sit &quot;insecurely.&quot;
&gt; (Note: I have been having weird net connection problems for a week or two.
&gt; It's been ultra slow. If there is a connection problem on Sunday, we can 
&gt; move
&gt; the challenge to whatever time I can connect. The downtime is 
&gt; short-lived.)
&gt; 
&gt; Rooting for the visitors:
&gt; Some strategy is in order. Some of you may want to run rm -rf / as root 
&gt; while
&gt; others may want to install some type of virus or trojan. I suggest you use
&gt; this thread to coordinate that - so that you won't bump heads.
&gt; 
&gt; Challenge results:
&gt; The challenge will have no &quot;tie.&quot; I will either restore the system back to
&gt; clean state quickly (and outline how I did so), or I lose the competition.
&gt; 
&gt; IF I am unable to restore the system, I would like there to be a 
&gt; consequence.
&gt; That's what makes challenges fun. Perhaps I can fund the pizza for the 
&gt; next
&gt; Installfest ($100 worth) or something like that.
&gt; 
&gt; IF I am able to restore the system and explain what steps I did to make 
&gt; sure
&gt; that it's &quot;clean&quot; and fully restored, Geoffrey will be responsible for
&gt; providing me with clear instructions on how to fix the SIX problems (with 
&gt; my
&gt; OS - not Gentoo :) ) that started this thread - within a reasonable amount 
&gt; of
&gt; time. The six problems include and are limited to: 1. Unstable browser. 2.
&gt; Reset mpu port to 300 3. Fix Gnutella 4. Get scanner working 5. Install 
&gt; IVTV
&gt; driver 6. Get noteedit to produce sound
&gt; I would like the instructions so that I can apply the changes *myself* 
&gt; (for
&gt; security reasons and to learn the solutions). I will forward the journals
&gt; that I kept on the issues and take significant steps to assist him.
&gt; 
&gt; My goals:
&gt; 1. To get my system fixed within a reasonable amount of time.
&gt; 2. To prove that I can safely run as root all of the time.
&gt; 
&gt; As you all know, I am NOT an expert. I don't like reading manuals much. 
&gt; Most
&gt; of the time, I don't even fully understand them. I am not a professional
&gt; system administrator. I am just a guy who uses Linux to get things done.
&gt; Thus, it should be easy for the group to defeat me in this challenge.
&gt; 
&gt; I hope the most vocal anti-run-as-root crowd who sometimes come off as
&gt; &quot;know-it-alls&quot; (i.e.: James Sumners, Jonathan Rickman, George Carless, 
&gt; Jason
&gt; Day, Jerald Sheets, et al) will be available to participate. Moreover, in 
&gt; the
&gt; event Geoffrey needs assistance, my hope is that the &quot;RTFM, It's not a 
&gt; Debian
&gt; problem&quot; people will help him.
&gt; --
&gt; Wishing you Happiness, Joy, and Laughter,
&gt; Drew Brown
&gt; <a  rel="nofollow" href="http://www.ChangingLINKS.com";>http://www.ChangingLINKS.com</a>
&gt; _______________________________________________
&gt; Ale mailing list
&gt; Ale at ale.org
&gt; <a  rel="nofollow" href="http://www.ale.org/mailman/listinfo/ale";>http://www.ale.org/mailman/listinfo/ale</a>
&gt;
-------------- next part --------------
An HTML attachment was scrubbed...



</pre>
<!--X-Body-of-Message-End-->
<!--X-MsgBody-End-->
<!--X-Follow-Ups-->
<hr>
<!--X-Follow-Ups-End-->
<!--X-References-->
<ul><li><strong>References</strong>:
<ul>
<li><strong><a name="00525" href="msg00525.html">[ale] Sunday 05-22-05 6PM RUN-AS-ROOT CHALLENGE</a></strong>
<ul><li><em>From:</em> groups at ChangingLINKS.com (ChangingLINKS.com)</li></ul></li>
</ul></li></ul>
<!--X-References-End-->
<!--X-BotPNI-->
<ul>
<li>Prev by Date:
<strong><a href="msg00552.html">[ale] Linux Distributions</a></strong>
</li>
<li>Next by Date:
<strong><a href="msg00554.html">[ale] [OT] I want to become a ham</a></strong>
</li>
<li>Previous by thread:
<strong><a href="msg00726.html">[ale] Sunday 05-22-05 6PM RUN-AS-ROOT CHALLENGE</a></strong>
</li>
<li>Next by thread:
<strong><a href="msg00641.html">[ale] Sunday 05-22-05 6PM RUN-AS-ROOT CHALLENGE</a></strong>
</li>
<li>Index(es):
<ul>
<li><a href="maillist.html#00553"><strong>Date</strong></a></li>
<li><a href="threads.html#00553"><strong>Thread</strong></a></li>
</ul>
</li>
</ul>

<!--X-BotPNI-End-->
<!--X-User-Footer-->
<!--X-User-Footer-End-->
</body>
</html>