Concerned about my security

MrFried
Posts: 3
Joined: Mon Dec 12, 2011 3:17 am

Concerned about my security

Postby MrFried » Mon Dec 12, 2011 3:30 am

Hi All,

This is my first post and I have to say that Amahi is a super cool product. Having said that I am a bit concerned and I am hoping that someone can help me to clarify some strange behaviour.

My background in IT is as a storage and DR specialist, working on EMC Clariion, Dell Equallogic, Compellent and Powervault gear. I am quite strong in Windows/VMware/Hardware but not so much in Linux or with DNS. I just logged into my HDA which I am in the process of building up 2 x MD RAIDS on (Super cool) and discovered a login by a system that does not belong on my network. I looked up the IP and did a Whois and discovered it was from a wierd IP in the bahamas.

http://i.imgur.com/9R84b.jpg

I have not yet configured the HDA to take over DNS or DHCP and am behind a firewall with no port forwarding configured so I am wondering how this system/IP was able to gain access to my system.

I am not to keen to proceed with the install unless someone can help me to understand where this login came from. Hopefully I am just being an idiot.

EDIT: I think this may be a wierd DNS entry. I am going to take a closer look and try to figure it out.

BTW Once I am up and running + happy I am stable and secure, I will definitely be making a donation 8D

Thanks,
Christian
HDA: AMD A64 250@1.06ghz + 4GB DDR1333 + 2 x 250GB Samsung SP2405C in MD RAID1 + 3 x 2TB WD20EARS in MD RAID5
Workstation: Intel i72600k + 16GB DDR1833 + RADEON 6970 + OCZ Agility3 SSD + Dell PERC5i with 3 x Samsung 1TB F3 in RAID5
Laptop: Dell Latitude E6400 + 4GB RAM + 500GB 7.2K WD BLACK

User avatar
bigfoot65
Project Manager
Posts: 11924
Joined: Mon May 25, 2009 4:31 pm

Re: Concerned about my security

Postby bigfoot65 » Mon Dec 12, 2011 5:59 am

Not sure where this would come from and how its related to Amahi. Amahi does does push patches to the platform occasionally, but the servers are located in California. I am not aware of it being capable of logging into systems as your pictures describe.

BTW, cross posting is not permitted. Your second post has been removed. Please give folks a chance to reply as this is an all volunteer community.
ßîgƒσστ65
Applications Manager

My HDA: Intel(R) Core(TM) i5-3570K CPU @ 3.40GHz on MSI board, 16GB RAM, 1TBx1+2TBx2+4TBx2

MrFried
Posts: 3
Joined: Mon Dec 12, 2011 3:17 am

Re: Concerned about my security

Postby MrFried » Mon Dec 12, 2011 2:46 pm

Hi Bigfoot,

Thanks for your reply. I figured out the issue and that is DNS appears to be working incorrectly and has given my main system 2 separate DNS entries (H005 and USER-PC). I have experience with M$ DNS but linux is a whole new experience for me =)

I suspect that this may be due to 2 reasons.

i. My router DHCP had assigned my PC an IPV6 and IPV4 address.
ii. I ran my HDA for about a day while still using the DHCP and DNS on my router.

I am going to be re-installing anyway as I managed to make a very interesting partition layout for my 2 x 250GB boot drives that are in an MD raid1.

Thanks,
Christian
HDA: AMD A64 250@1.06ghz + 4GB DDR1333 + 2 x 250GB Samsung SP2405C in MD RAID1 + 3 x 2TB WD20EARS in MD RAID5
Workstation: Intel i72600k + 16GB DDR1833 + RADEON 6970 + OCZ Agility3 SSD + Dell PERC5i with 3 x Samsung 1TB F3 in RAID5
Laptop: Dell Latitude E6400 + 4GB RAM + 500GB 7.2K WD BLACK

Who is online

Users browsing this forum: No registered users and 23 guests