Re: Hacked?

From: Blaine Kahle (goatee_at_binary.net)
Date: 05/11/03

  • Next message: Mikko Työläjärvi: "Re: Hacked?"
    Date: Sun, 11 May 2003 13:03:21 -0500
    To: Brett Glass <brett@lariat.org>
    
    

    On Fri, May 09, 2003 at 11:01:21AM -0600, Brett Glass wrote:
    > At 08:25 AM 5/9/2003, Bjoern A. Zeeb wrote:
    >
    > >this asumes that truss is ok ;-) perhaps take the truss from your
    > >other 4.7 machine ...
    >
    > Yes, you do have to be careful of this. I recently investigated a
    > machine that had been "owned," and when truss was applied to some
    > commands (e.g. netstat) it produced no output.

    I'm showing that truss'ing netstat produces no output on several
    versions of FreeBSD that I have installed. Is this correct behavior? The
    truss and netstat binaries both check out when compared to the listings
    at http://www.knowngoods.org/

    -- 
    Blaine Kahle
    blaine@binary.net
    0x178AA0E0
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    

  • Next message: Mikko Työläjärvi: "Re: Hacked?"

    Relevant Pages

    • Re: Network configuration in FreeBSD
      ... the netstat reads: ... inet 127.0.0.1 netmask 0xff000000 ... Send the list the output of the following commands: ... Internet: ...
      (freebsd-questions)
    • Re: Hacked?
      ... you do have to be careful of this. ... > I'm showing that truss'ing netstat produces no output on several ... > truss and netstat binaries both check out when compared to the listings ... If you really need to truss it, make a copy and run it as a user ...
      (FreeBSD-Security)
    • Re: CMD commands hang
      ... Is your Firewall blocking IPconfig, ping and netstat? ... I booted in SafeMode with networking and all these commands work fine. ...
      (microsoft.public.windowsxp.help_and_support)
    • Re: Network configuration in FreeBSD
      ... Send the list the output of the following commands: ... netstat -rn ... (plug the USB flash disk into a USB socket) ...
      (freebsd-questions)
    • Re: How to monitor network bandwith
      ... It depends what you mean by "busy %". ... in use, then netstat will be able to tell you that, but it's not very useful ... How to monitor network bandwith ... > 'netstat' and 'entstat' commands; ...
      (AIX-L)