Gentoo Archives: gentoo-user

From: Grant <emailgrant@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Re: Did I just get hacked???
Date: Mon, 12 Feb 2007 18:17:57
Message-Id: 49bf44f10702121005tffea02ayce436b96bf2274c0@mail.gmail.com
In Reply to: Re: [gentoo-user] Re: Did I just get hacked??? by Dan Farrell
1 > > > > A good rootkit will install a "ps" that won't show the 'bot
2 > > > > processes. The one time a machine of mine got hacked, netstat
3 > > > > still worked, but I don't know why a hacked netstat couldn't be
4 > > > > installed as well.
5 > > >
6 > > > > Looking through /proc/˜pid> is probably still reliable.
7 > > >
8 > > >
9 > > > Hello Grant,
10 > > >
11 > > > I keep an old portable around, running wireshark and a flat hub.
12 > > > You can set your ethernet address to 0.0.0.0 and fire up wireshark.
13 > > >
14 > > > You can then sniff any (ethernet) segment of your network for
15 > > > nefarious traffic or male-configured network applictions.
16 > > >
17 > > > hth,
18 > > >
19 > > > James
20 > >
21 > > I can see in an xfce4 panel plugin that there is constantly a small
22 > > amount of incoming/outgoing traffic to/from the affected system when
23 > > there is no reason I know of for it. netstat doesn't show anything
24 > > that jumps out at me although this is the first time I've really used
25 > > it. All of the current netstat connections appear to be UNIX as
26 > > opposed to Internet. Should I paste them in?
27 > >
28 > > - Grant
29 > > [Error decoding BASE64]
30 > nope, they're all local socket connections. What kind of traffic are
31 > you seeing, i mean how much? Ever heard of tcpdump?
32
33 I just did a fresh reboot and as soon as xfce4 was loaded I was seeing
34 between .2kbps and .6kbps incoming and outgoing traffic constantly in
35 the xfce4 panel plugin which uses /proc/net/dev. I then changed the
36 WPA wireless password on the router so the machine couldn't connect
37 and the panel plugin started reporting small bursts of
38 incoming/outgoing traffic instead of the constant stream. I then
39 updated the machine's password to match the router's new password and
40 the steady stream returned.
41
42 netstat --ip reports absolutely no connections during all of this.
43
44 Should I emerge tcpdump and run that?
45
46 - Grant

Replies

Subject Author
Re: [gentoo-user] Re: Did I just get hacked??? "nicolas.cornu" <nicolas.cornu@××××××××××××.fr>