Grant Edwards <grante <at> visi.com> writes:


> A good rootkit will install a "ps" that won't show the 'bot
> processes.  The one time a machine of mine got hacked, netstat
> still worked, but I don't know why a hacked netstat couldn't be
> installed as well.

> Looking through /proc/≤pid> is probably still reliable.


Hello Grant,

I keep an old portable around, running wireshark and a flat hub.
You can set your ethernet address to 0.0.0.0 and fire up wireshark.

You can then sniff any (ethernet) segment of your network for
nefarious traffic or male-configured network applictions.

hth,

James




-- 
gentoo-user@gentoo.org mailing list

Reply via email to