1 |
On Wednesday 19 September 2007, Grant wrote: |
2 |
|
3 |
> I recognize everything in 'ps -ef' I think, but I've never really used |
4 |
> netstat before. Under "Active Internet connections" I don't |
5 |
> recognize: |
6 |
> |
7 |
> tcp localhost:10030 |
8 |
> tcp *:snpp |
9 |
|
10 |
Hmm, are you running postfix on this server (just a suspicion). |
11 |
|
12 |
Also, snpp is for pagers: |
13 |
http://en.wikipedia.org/wiki/Simple_Network_Paging_Protocol |
14 |
|
15 |
Run # netstat -anop which will show you the process owner. Hopefully, if |
16 |
there is something running it will show up (clever scripts can mask |
17 |
themselves from netstat, ps auxf, etc.). |
18 |
|
19 |
Then run lsof (check man lsof) to see if there is anything suspicious there, |
20 |
like another user logged in either as root or with a different name. |
21 |
|
22 |
Finally, ask your ISP to boot off a LiveCD and scan the machine with rkhunter |
23 |
and chrootkit. |
24 |
|
25 |
Depending on how many thousands of tickets the database had the crackers may |
26 |
or may have not found out about your root passwd. On the other hand, if you |
27 |
can't sleep at nights it is better to format and reinstall. |
28 |
|
29 |
HTH. |
30 |
-- |
31 |
Regards, |
32 |
Mick |