Gentoo Archives: gentoo-user

From: Volker Armin Hemmann <volker.armin.hemmann@××××××××××××.de>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Hacked by association?
Date: Sat, 22 Sep 2007 00:24:29
Message-Id: 200709220210.51366.volker.armin.hemmann@tu-clausthal.de
1 On Samstag, 22. September 2007, Grant wrote:
2 > > > Do I
3 > > > need to start this thing over?
4 > >
5 > > yes. No tool can tell you for certain, that no malware is rampage on your
6 > > system. netstat, ps, emerge might be hacked already. As might be md5sum
7 > > and other tools to generate and compare ckecksums. There is only one way
8 > > to make sure your system is clean:
9 > >
10 > > reinstallation
11 >
12 > I had another idea. Would it work to monitor my machine's traffic
13 > from another machine on the network and determine if I've been hacked
14 > that way? Any ssh traffic other than mine would be a giveaway.
15 >
16 > - Grant
17
18 and who says that the hacker uses ssh in the future? or connects to the box in
19 the next couple of weeks?
20 --
21 gentoo-user@g.o mailing list