Gentoo Archives: gentoo-user

From: "nicolas.cornu" <nicolas.cornu@××××××××××××.fr>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Re: Did I just get hacked???
Date: Tue, 13 Feb 2007 08:18:07
Message-Id: 45D171C5.2010609@ch-st-julien.fr
In Reply to: Re: [gentoo-user] Re: Did I just get hacked??? by Grant
1 Grant wrote:
2
3 >> > > > A good rootkit will install a "ps" that won't show the 'bot
4 >> > > > processes. The one time a machine of mine got hacked, netstat
5 >> > > > still worked, but I don't know why a hacked netstat couldn't be
6 >> > > > installed as well.
7 >> > >
8 >> > > > Looking through /proc/≤pid> is probably still reliable.
9 >> > >
10 >> > >
11 >> > > Hello Grant,
12 >> > >
13 >> > > I keep an old portable around, running wireshark and a flat hub.
14 >> > > You can set your ethernet address to 0.0.0.0 and fire up wireshark.
15 >> > >
16 >> > > You can then sniff any (ethernet) segment of your network for
17 >> > > nefarious traffic or male-configured network applictions.
18 >> > >
19 >> > > hth,
20 >> > >
21 >> > > James
22 >> >
23 >> > I can see in an xfce4 panel plugin that there is constantly a small
24 >> > amount of incoming/outgoing traffic to/from the affected system when
25 >> > there is no reason I know of for it. netstat doesn't show anything
26 >> > that jumps out at me although this is the first time I've really used
27 >> > it. All of the current netstat connections appear to be UNIX as
28 >> > opposed to Internet. Should I paste them in?
29 >> >
30 >> > - Grant
31 >> > [Error decoding BASE64]
32 >> nope, they're all local socket connections. What kind of traffic are
33 >> you seeing, i mean how much? Ever heard of tcpdump?
34 >
35 >
36 > I just did a fresh reboot and as soon as xfce4 was loaded I was seeing
37 > between .2kbps and .6kbps incoming and outgoing traffic constantly in
38 > the xfce4 panel plugin which uses /proc/net/dev. I then changed the
39 > WPA wireless password on the router so the machine couldn't connect
40 > and the panel plugin started reporting small bursts of
41 > incoming/outgoing traffic instead of the constant stream. I then
42 > updated the machine's password to match the router's new password and
43 > the steady stream returned.
44 >
45 > netstat --ip reports absolutely no connections during all of this.
46 >
47 > Should I emerge tcpdump and run that?
48 >
49 > - Grant
50 > │ИМ╒▀╛z╦·з(╒╦&j)b· b
51 > st==
52
53 Hi,
54
55 You could try wireshark which is almost the same thing as tcpdump but
56 graphical. it will help you to analyze the packets going through your
57 interface.
58
59
60 --
61 gentoo-user@g.o mailing list