Re: Linux Backdoor

From: smg (
Date: 11/30/02

From: "smg" <>
Date: Sat, 30 Nov 2002 04:05:09 GMT

"Nicholas Johnson" <> wrote in message
> What should I look for if I think there is a backdoor installed on my box?


The advice about using "chkrootkit" is good. Try it out and see if it finds
anything on your system. . This will be the easiest approach and will catch
about 95% of all hacked systems, in my experience at least.

>From the outside looking in, you could also try using a port scanner to see
what ports are open/accepting connections and then compare them to the known
services you are running. This can be daunting for a newcomer but it tends
to be
an invaluable lesson, well worth the effort to investigate each port to
determine if
there are in fact "backdoors" open on your host. At the same time, you will
lots about services and ports.

NMAP is a great portscanning tool and is relatively easy to use.

Good luck,

