Re: hidden processes

From: gminick (gminick_at_bsd.sim.pl)
Date: 07/31/03

  • Next message: Adam Overlin: "RE: Cisco Workaround"
    Date: Thu, 31 Jul 2003 19:50:23 +0200
    To: security-basics@securityfocus.com
    
    

    On Wed, Jul 30, 2003 at 05:28:22PM -0400, Vlady wrote:
    > Hi,
    > One of my mashines is hacked and chkrootkit-0.40 tells me that I have 3
    > proccess hidden from "ps". All of my system binaries looks like beeing clean.
    > Using "netstat" I can see that there is not a lisenning servise other than the
    > services suppused to work on the machine.
    > I know that the best way to go further is to reinstall the machine but first I
    > would like to understand more of what have happend.
    Do you know of:
    <https://listman.redhat.com/archives/phoebe-list/2003-February/msg01943.html>
    ?

    --
    [ Wojtek Walczak - gminick (at) underground.org.pl ]
    [       <http://underground.org.pl/gminick/>       ]
    [ "...rozmaite zwroty, matowe od patyny dawnosci." ]
    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------
    

  • Next message: Adam Overlin: "RE: Cisco Workaround"

    Relevant Pages

    • Re: How to audit dir/file access?
      ... Have you ever heard about lsof? ... ["...rozmaite zwroty, matowe od patyny dawnosci." ...
      (comp.os.linux.security)
    • Re: Compromised system help
      ... > If this is indeed a hacker compromise, you should be very interested in ... configure it after reinstall. ... ["...rozmaite zwroty, matowe od patyny dawnosci." ...
      (comp.os.linux.security)
    • Re: UDP sockets
      ... > timeout in an select for one socket? ... ["...rozmaite zwroty, matowe od patyny dawnosci." ...
      (comp.lang.python)
    • Re: Special Feature: R00ting The Hacker
      ... they all are different and that's why a stories like that have ... ["...rozmaite zwroty, matowe od patyny dawnosci." ...
      (comp.os.linux.security)
    • Re: freeswan
      ... ["...rozmaite zwroty, matowe od patyny dawnosci." ...
      (comp.os.linux.security)