Gentoo Archives: gentoo-user

From: Mick <michaelkintzios@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Hacked by association?
Date: Wed, 19 Sep 2007 19:43:07
Message-Id: 200709192023.34859.michaelkintzios@gmail.com
In Reply to: Re: [gentoo-user] Hacked by association? by Grant
1 On Wednesday 19 September 2007, Grant wrote:
2
3 > I recognize everything in 'ps -ef' I think, but I've never really used
4 > netstat before. Under "Active Internet connections" I don't
5 > recognize:
6 >
7 > tcp localhost:10030
8 > tcp *:snpp
9
10 Hmm, are you running postfix on this server (just a suspicion).
11
12 Also, snpp is for pagers:
13 http://en.wikipedia.org/wiki/Simple_Network_Paging_Protocol
14
15 Run # netstat -anop which will show you the process owner. Hopefully, if
16 there is something running it will show up (clever scripts can mask
17 themselves from netstat, ps auxf, etc.).
18
19 Then run lsof (check man lsof) to see if there is anything suspicious there,
20 like another user logged in either as root or with a different name.
21
22 Finally, ask your ISP to boot off a LiveCD and scan the machine with rkhunter
23 and chrootkit.
24
25 Depending on how many thousands of tickets the database had the crackers may
26 or may have not found out about your root passwd. On the other hand, if you
27 can't sleep at nights it is better to format and reinstall.
28
29 HTH.
30 --
31 Regards,
32 Mick

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-user] Hacked by association? Grant <emailgrant@×××××.com>