Page 1 of 1

Concerned about my security

Posted: Mon Dec 12, 2011 3:30 am
by MrFried
Hi All,

This is my first post and I have to say that Amahi is a super cool product. Having said that I am a bit concerned and I am hoping that someone can help me to clarify some strange behaviour.

My background in IT is as a storage and DR specialist, working on EMC Clariion, Dell Equallogic, Compellent and Powervault gear. I am quite strong in Windows/VMware/Hardware but not so much in Linux or with DNS. I just logged into my HDA which I am in the process of building up 2 x MD RAIDS on (Super cool) and discovered a login by a system that does not belong on my network. I looked up the IP and did a Whois and discovered it was from a wierd IP in the bahamas.

http://i.imgur.com/9R84b.jpg

I have not yet configured the HDA to take over DNS or DHCP and am behind a firewall with no port forwarding configured so I am wondering how this system/IP was able to gain access to my system.

I am not to keen to proceed with the install unless someone can help me to understand where this login came from. Hopefully I am just being an idiot.

EDIT: I think this may be a wierd DNS entry. I am going to take a closer look and try to figure it out.

BTW Once I am up and running + happy I am stable and secure, I will definitely be making a donation 8D

Thanks,
Christian

Re: Concerned about my security

Posted: Mon Dec 12, 2011 5:59 am
by bigfoot65
Not sure where this would come from and how its related to Amahi. Amahi does does push patches to the platform occasionally, but the servers are located in California. I am not aware of it being capable of logging into systems as your pictures describe.

BTW, cross posting is not permitted. Your second post has been removed. Please give folks a chance to reply as this is an all volunteer community.

Re: Concerned about my security

Posted: Mon Dec 12, 2011 2:46 pm
by MrFried
Hi Bigfoot,

Thanks for your reply. I figured out the issue and that is DNS appears to be working incorrectly and has given my main system 2 separate DNS entries (H005 and USER-PC). I have experience with M$ DNS but linux is a whole new experience for me =)

I suspect that this may be due to 2 reasons.

i. My router DHCP had assigned my PC an IPV6 and IPV4 address.
ii. I ran my HDA for about a day while still using the DHCP and DNS on my router.

I am going to be re-installing anyway as I managed to make a very interesting partition layout for my 2 x 250GB boot drives that are in an MD raid1.

Thanks,
Christian