1 |
> > > > A good rootkit will install a "ps" that won't show the 'bot |
2 |
> > > > processes. The one time a machine of mine got hacked, netstat |
3 |
> > > > still worked, but I don't know why a hacked netstat couldn't be |
4 |
> > > > installed as well. |
5 |
> > > |
6 |
> > > > Looking through /proc/˜pid> is probably still reliable. |
7 |
> > > |
8 |
> > > |
9 |
> > > Hello Grant, |
10 |
> > > |
11 |
> > > I keep an old portable around, running wireshark and a flat hub. |
12 |
> > > You can set your ethernet address to 0.0.0.0 and fire up wireshark. |
13 |
> > > |
14 |
> > > You can then sniff any (ethernet) segment of your network for |
15 |
> > > nefarious traffic or male-configured network applictions. |
16 |
> > > |
17 |
> > > hth, |
18 |
> > > |
19 |
> > > James |
20 |
> > |
21 |
> > I can see in an xfce4 panel plugin that there is constantly a small |
22 |
> > amount of incoming/outgoing traffic to/from the affected system when |
23 |
> > there is no reason I know of for it. netstat doesn't show anything |
24 |
> > that jumps out at me although this is the first time I've really used |
25 |
> > it. All of the current netstat connections appear to be UNIX as |
26 |
> > opposed to Internet. Should I paste them in? |
27 |
> > |
28 |
> > - Grant |
29 |
> > [Error decoding BASE64] |
30 |
> nope, they're all local socket connections. What kind of traffic are |
31 |
> you seeing, i mean how much? Ever heard of tcpdump? |
32 |
|
33 |
I just did a fresh reboot and as soon as xfce4 was loaded I was seeing |
34 |
between .2kbps and .6kbps incoming and outgoing traffic constantly in |
35 |
the xfce4 panel plugin which uses /proc/net/dev. I then changed the |
36 |
WPA wireless password on the router so the machine couldn't connect |
37 |
and the panel plugin started reporting small bursts of |
38 |
incoming/outgoing traffic instead of the constant stream. I then |
39 |
updated the machine's password to match the router's new password and |
40 |
the steady stream returned. |
41 |
|
42 |
netstat --ip reports absolutely no connections during all of this. |
43 |
|
44 |
Should I emerge tcpdump and run that? |
45 |
|
46 |
- Grant |