Gentoo Archives: gentoo-user

From: Ryan Sims <rwsims@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Hacked by association?
Date: Wed, 19 Sep 2007 19:25:28
Message-Id: 64e8d2f20709191211y39fb1d34u27bfaf7be6dd92b9@mail.gmail.com
In Reply to: Re: [gentoo-user] Hacked by association? by Grant
1 On 9/19/07, Grant <emailgrant@×××××.com> wrote:
2 > > > Last night my host sent out a message that their database had been
3 > > > compromised. I contacted them this morning and it turns out that all
4 > > > of their trouble tickets were exposed. I checked my records and
5 > > > (stupidly) I had included my root password in an email to them about a
6 > > > year ago. I (stupidly) hadn't changed the password since. I've
7 > > > changed it now and rebooted the system, but what do you think? Do I
8 > > > need to start this thing over?
9 > > >
10 > > > - Grant
11 > >
12 > > I think you should take a look at the programs that
13 > > are running, and netstat -l, and see if anything is fishy.
14 >
15 > I recognize everything in 'ps -ef' I think, but I've never really used
16 > netstat before. Under "Active Internet connections" I don't
17 > recognize:
18 >
19 > tcp localhost:10030
20 > tcp *:snpp
21 >
22 > I don't recognize most of the paths under UNIX domain sockets.
23 > Anything particular I should look for?
24
25 Try using the -p option to netstat to get the PID of those two
26 connections, see if its anything suspicious
27
28
29 --
30 Ryan W Sims
31 --
32 gentoo-user@g.o mailing list