Re: how to tell when you have a hacker?

Top Page
Attachments:
Message as email
+ (text/plain)
Delete this message
Reply to this message
Author: Jeremy C. Reed
Date:  
To: Main PLUG discussion list
New-Topics: lkm trojan
Subject: Re: how to tell when you have a hacker?
On Fri, 17 Feb 2006, Mike wrote:

> Well, it seems it is all okay (not that I would know). I suppose I should run
> chkroot kit daily and see if anything new shoes up.


I don't think it is okay.

> >     Checking 'lkm' ... You have      4 process hidden for ps command
> >     Warning: Possible LKM Trojan installed

> >
> > Is this bad?


Yes.

I would track that down more. Install tcpdump and then run it to see yoru
network traffic. But then again, that may not help if something hides its
tracks there too.

Disconnect the box from the internet. Reboot with a live CD and use it to
research your problem more. (Using the md5sum example I showed in other
email as one thing to do.)

Jeremy C. Reed

                 Media Relations and Publishing Services
                http://www.reedmedia.net/
---------------------------------------------------
PLUG-discuss mailing list - 
To subscribe, unsubscribe, or to change  you mail settings:
http://lists.PLUG.phoenix.az.us/mailman/listinfo/plug-discuss