What are the security measures to protect an MX Linux machine from Ransomware?

Message
Author
joejac
Posts: 102
Joined: Sat Apr 30, 2016 1:25 pm

What are the security measures to protect an MX Linux machine from Ransomware?

#1 Post by joejac »

Hello,

I appreciate some information on hardening MX Linux security and specially: what are the security measures to protect an MX Linux machine from Ransomware?

Thank you and regards
joejac

User avatar
Gordon Cooper
Posts: 965
Joined: Mon Nov 21, 2011 5:50 pm

Re: What are the security measures to protect an MX Linux machine from Ransomware?

#2 Post by Gordon Cooper »

In that the recent world-wide Ransomware episode happened because of (1) a deficiency in Windows system coding and (2) the failure by many users to install the manufacturer's patch to repair that deficiency (users had about two months to do this before the episode), Linux overall was immune.

However, this may not be a permanent immunity, so all users need to take some responsibility for keeping their equipment free from malware. Be careful what you download and open. Some related reading is at: https://en.wikipedia.org/wiki/Computer_worm, with links to related pages about virus etc.
Backup: Dell9010, MX-19_B2, Win7, 120 SSD, WD 232GIB HD, 4GB RAM
Primary :Homebrew64 bit Intel duo core 2 GB RAM, 120 GB Kingston SSD, Seagate1TB.
MX-18.2 64bit. Also MX17, Kubuntu14.04 & Puppy 6.3.

joejac
Posts: 102
Joined: Sat Apr 30, 2016 1:25 pm

Re: What are the security measures to protect an MX Linux machine from Ransomware?

#3 Post by joejac »

Thank you Gordon.
Regards
joejac

User avatar
rokytnji.1
Global Moderator
Posts: 718
Joined: Sun Apr 13, 2014 9:06 pm

Re: What are the security measures to protect an MX Linux machine from Ransomware?

#4 Post by rokytnji.1 »

Well, wine does not come as a default install when you install MX. I call that a plus and a preventive measure. It is up to the user/option to run Windows stuff in MX.

All I can say as a AntiX long time user and team member. Plus a Mepis/MX user since version 6.0. Nobody has hijacked/pwnd my gear in all these years.
But I now know how to drive these things a little better than when I 1st started.

I wonder though. Because I don't really know. If users running XP,Vista, 7, 8, 10 in VM can say the same I just said. I mentioned wine because of this.
2. Can I get affected by using Wine?

Short answer: Yes. Since Wine emulates almost every behavior of the Windows environment, the worm can actually try to find ways on how it can affect you. The worst case scenario is that depending on the direct access wine has to your Ubuntu system, some or all parts of your home will be affected (Did not fully test this. See answer 4 below), although I see a lot of roadblocks here for how the worm behaves and how it would try to encrypt a non ntfs/fat partition/files and what non-super admin permission would it need to do this, even coming from Wine, so it does not have full powers like on Windows. In any case, it's better to play on the safe side for this.
Source: https://askubuntu.com/questions/914623/ ... inux-users

skidoo
Posts: 753
Joined: Tue Sep 22, 2015 6:56 pm

Re: What are the security measures to protect an MX Linux machine from Ransomware?

#5 Post by skidoo »

hardening:
Do not autostart unneeded services. Disable any pre-installed services you don't plan to use. Blacklist any unneed/unwanted kernel modules.
References, for study:
https://github.com/fcaviggia/hardening- ... acklist.sh
https://linux-audit.com/kernel-hardenin ... x-modules/
http://bookofzeus.com/harden-ubuntu/
http://bastille-linux.sourceforge.net/R ... eport.html
https://linux-audit.com/linux-server-ha ... e-systems/
https://www.cyberciti.biz/tips/linux-security.html

=====================

employ a reasonably-configured firewall (and,whenever possible, connect your system from behind a NAT router)

=====================

(read about and) apt-get install firejail
so that you can run individual programs in a sandbox

=====================

To prevent accidental launching of root-permissioned firefox, you can create an empty, read-only file /root/.mozilla
Accidental? Yeah, like if you've launched `gksu thunar` for instance...
if you click its "about} Help" button, it might (I don't recall) open a browser and attempt to retrieve the online docs from hzzp://xfce.org
Quite a few programs nowadays rig the Help button to load online docs.

=====================

"hardening" is only half a solution.
Here are a few "common sense" BestPractices:


Be mindful when running 'code found online'
and
Never copy/paste web-snipped code directly into terminal !
ref: https://nakedsecurity.sophos.com/2016/0 ... web-pages/
ref: http://thejh.net/misc/website-terminal-copy-paste
ref: https://news.ycombinator.com/item?id=5508225
ref: https://www.reddit.com/r/netsec/comment ... inal_demo/

Similarly, I would never (but it's becoming an increasingly common practice)
paste a found-on-the-web commandline involving curl (or wget) ...and sudo (and/or `sh` or `bash`)
curl http:/gitmeuptodate/iwantapony .......... | sudo -h somescript.sh
(Same goes for blindly performing `git clone hzzp:/zingerbuster ... | sudo makemeasandwich)

=====================

Install & use defensive browser extensions, like: uBlock, RequestPolicy, AdblockPlusMinusSquared...
(to marshal which 3rd-party sites your browser interacts with)

Educate yourself:
Decide which "default, as-shipped" browser preferences are "sane" (vs not)
https://www.ghacks.net/2017/04/30/firef ... s-changes/
https://github.com/ghacksuserjs/ghacks-user.js

joejac
Posts: 102
Joined: Sat Apr 30, 2016 1:25 pm

Re: What are the security measures to protect an MX Linux machine from Ransomware?

#6 Post by joejac »

Hello and thanks a lot to all for this valuable information.
Best regards
joejac

seco
Posts: 1
Joined: Mon Mar 12, 2018 2:17 pm

Re: What are the security measures to protect an MX Linux machine from Ransomware?

#7 Post by seco »

The No. 1 rule for protecting Linux in general is updating!
However, I review this list when creating a new node
I love paranoid security tools which send a mail for every change happened.
Regards,

User avatar
Jerry3904
Administrator
Posts: 21943
Joined: Wed Jul 19, 2006 6:13 am

Re: What are the security measures to protect an MX Linux machine from Ransomware?

#8 Post by Jerry3904 »

Great for servers, though I doubt about its relevancy for our users. We have sysadmins using MX, but I can't remember anyone running MX on a server (except for personal use).

BTW: this is an old thread, and it is usually better to start a clean thread in such a case.
Production: 5.10, MX-23 Xfce, AMD FX-4130 Quad-Core, GeForce GT 630/PCIe/SSE2, 16 GB, SSD 120 GB, Data 1TB
Personal: Lenovo X1 Carbon with MX-23 Fluxbox and Windows 10
Other: Raspberry Pi 5 with MX-23 Xfce Raspberry Pi Respin

User avatar
rokytnji.1
Global Moderator
Posts: 718
Joined: Sun Apr 13, 2014 9:06 pm

Re: What are the security measures to protect an MX Linux machine from Ransomware?

#9 Post by rokytnji.1 »

I've been through a past experience where I used these tools to check certain things out.

https://haveibeenpwned.com/Passwords
https://haveibeenpwned.com/

Edit: Just saw the necro reference. I can delete my post if you wish. :popcorn:

User avatar
Jan K.
Posts: 32
Joined: Mon Jan 28, 2019 8:52 am

Re: What are the security measures to protect an MX Linux machine from Ransomware?

#10 Post by Jan K. »

Unless there's something wrong with Lynis... :crossfingers: Security Auditing Tool https://cisofy.com/lynis/

Looks nice to me, have no experience with it, but have planned to use it on "the upcoming install" (tm)...

Anyone with experience of it?

Post Reply

Return to “General”