Re: TRD like tool for linux?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]



On Wed, Apr 16, 2014 at 9:57 AM, zep <zgreenfelder@xxxxxxxxx> wrote:
> so I found that one of my VM hosts seems to have been compromised in
> some way; I've shut it down, isolated it, found a few odd things like
> gibberish comments and odd hostnames that I don't recognise pointed back
> to 127.0.0.1 in /etc/hosts.  I tried TRD and it seems mildly useful, but
> has more of a windowsy feel for what it wants to be able to fix.   does
> anyone know of something with more linux rootkit detection as a focus?
> I could just rebuild this machine, but I'd like to know for sure what
> all/how bad this was broken so I can avoid it for next time.

Brute force sometimes works... If you have a backup from before the
issue, restore it somewhere and diff -r (or maybe rsync -av --delete
if it is remote) to find what changed.

-- 
  Les Mikesell
    lesmikesell@xxxxxxxxx
_______________________________________________
CentOS mailing list
CentOS@xxxxxxxxxx
http://lists.centos.org/mailman/listinfo/centos




[Index of Archives]     [CentOS]     [CentOS Announce]     [CentOS Development]     [CentOS ARM Devel]     [CentOS Docs]     [CentOS Virtualization]     [Carrier Grade Linux]     [Linux Media]     [Asterisk]     [DCCP]     [Netdev]     [Xorg]     [Linux USB]
  Powered by Linux