Gentoo Archives: gentoo-user

From: Grant <emailgrant@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Hacked by association?
Date: Wed, 19 Sep 2007 23:29:26
Message-Id: 49bf44f10709191616u4939b86dla32ef38067ea7702@mail.gmail.com
In Reply to: Re: [gentoo-user] Hacked by association? by Mick
1 > > I recognize everything in 'ps -ef' I think, but I've never really used
2 > > netstat before. Under "Active Internet connections" I don't
3 > > recognize:
4 > >
5 > > tcp localhost:10030
6 > > tcp *:snpp
7 >
8 > Also, snpp is for pagers:
9 > http://en.wikipedia.org/wiki/Simple_Network_Paging_Protocol
10
11 With netstat -lp it looks like *:snpp is associated with apache2 and
12 is using the same pid as *:http and *:https. I've never set up
13 anything having to do with a pager. I've never had a pager. What can
14 I do to investigate that further?
15
16 > Then run lsof (check man lsof) to see if there is anything suspicious there,
17 > like another user logged in either as root or with a different name.
18
19 Any handy lsof commands?
20
21 - Grant
22 --
23 gentoo-user@g.o mailing list

Replies

Subject Author
Re: [gentoo-user] Hacked by association? Jerry McBride <mcbrides9@×××××××.net>
Re: [gentoo-user] Hacked by association? Grant <emailgrant@×××××.com>
Re: [gentoo-user] Hacked by association? Mick <michaelkintzios@×××××.com>
Re: [gentoo-user] Hacked by association? Hans-Werner Hilse <hilse@×××.de>
[gentoo-user] Re: Hacked by association? Alexander Skwar <listen@×××××××××××××××.name>