Grant Edwards <grante <at> visi.com> writes:
> A good rootkit will install a "ps" that won't show the 'bot > processes. The one time a machine of mine got hacked, netstat > still worked, but I don't know why a hacked netstat couldn't be > installed as well. > Looking through /proc/≤pid> is probably still reliable. Hello Grant, I keep an old portable around, running wireshark and a flat hub. You can set your ethernet address to 0.0.0.0 and fire up wireshark. You can then sniff any (ethernet) segment of your network for nefarious traffic or male-configured network applictions. hth, James -- gentoo-user@gentoo.org mailing list