Gentoo Archives: gentoo-user

From: Grant <emailgrant@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Re: Did I just get hacked???
Date: Mon, 12 Feb 2007 04:05:03
Message-Id: 49bf44f10702111958i4624e0den3d76c0db7d2a5dde@mail.gmail.com
In Reply to: [gentoo-user] Re: Did I just get hacked??? by James
1 > > A good rootkit will install a "ps" that won't show the 'bot
2 > > processes. The one time a machine of mine got hacked, netstat
3 > > still worked, but I don't know why a hacked netstat couldn't be
4 > > installed as well.
5 >
6 > > Looking through /proc/˜pid> is probably still reliable.
7 >
8 >
9 > Hello Grant,
10 >
11 > I keep an old portable around, running wireshark and a flat hub.
12 > You can set your ethernet address to 0.0.0.0 and fire up wireshark.
13 >
14 > You can then sniff any (ethernet) segment of your network for
15 > nefarious traffic or male-configured network applictions.
16 >
17 > hth,
18 >
19 > James
20
21 I can see in an xfce4 panel plugin that there is constantly a small
22 amount of incoming/outgoing traffic to/from the affected system when
23 there is no reason I know of for it. netstat doesn't show anything
24 that jumps out at me although this is the first time I've really used
25 it. All of the current netstat connections appear to be UNIX as
26 opposed to Internet. Should I paste them in?
27
28 - Grant

Replies

Subject Author
Re: [gentoo-user] Re: Did I just get hacked??? Dan Farrell <dan@×××××××××.cx>