1 |
> > A good rootkit will install a "ps" that won't show the 'bot |
2 |
> > processes. The one time a machine of mine got hacked, netstat |
3 |
> > still worked, but I don't know why a hacked netstat couldn't be |
4 |
> > installed as well. |
5 |
> |
6 |
> > Looking through /proc/˜pid> is probably still reliable. |
7 |
> |
8 |
> |
9 |
> Hello Grant, |
10 |
> |
11 |
> I keep an old portable around, running wireshark and a flat hub. |
12 |
> You can set your ethernet address to 0.0.0.0 and fire up wireshark. |
13 |
> |
14 |
> You can then sniff any (ethernet) segment of your network for |
15 |
> nefarious traffic or male-configured network applictions. |
16 |
> |
17 |
> hth, |
18 |
> |
19 |
> James |
20 |
|
21 |
I can see in an xfce4 panel plugin that there is constantly a small |
22 |
amount of incoming/outgoing traffic to/from the affected system when |
23 |
there is no reason I know of for it. netstat doesn't show anything |
24 |
that jumps out at me although this is the first time I've really used |
25 |
it. All of the current netstat connections appear to be UNIX as |
26 |
opposed to Internet. Should I paste them in? |
27 |
|
28 |
- Grant |