--=-mlJj2IWsjOrmX+VVaPAW Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable This is the TUN/TAP device take a look into your kernel configurations into Networkiing options (IP: tunneling). you can check out : http://anchor.cs.binghamton.edu/~mobileip/LJ/index.html >hello >i'm running a redhat machine and while checking >[root@localhost root]# ifconfig -a >lo Link encap:Local Loopback > LOOPBACK MTU:16436 Metric:1 > RX packets:316 errors:0 dropped:0 overruns:0 frame:0 > TX packets:316 errors:0 dropped:0 overruns:0 carrier:0 > collisions:0 txqueuelen:0 > RX bytes:15800 (15.4 Kb) TX bytes:15800 (15.4 Kb) > >ppp0 Link encap:Point-to-Point Protocol > inet addr:62.135.14.214 P-t-P:172.17.9.205=20 Mask:255.255.255.255 > UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1524 Metric:1 > RX packets:1739 errors:0 dropped:0 overruns:0 frame:0 > TX packets:1942 errors:0 dropped:0 overruns:0 carrier:0 > collisions:0 txqueuelen:3 > RX bytes:528941 (516.5 Kb) TX bytes:178970 (174.7 Kb) > >tunl0 Link encap:IPIP Tunnel HWaddr > NOARP MTU:1480 Metric:1 > RX packets:0 errors:0 dropped:0 overruns:0 frame:0 > TX packets:0 errors:0 dropped:0 overruns:0 carrier:0 > collisions:0 txqueuelen:0 > RX bytes:0 (0.0 b) TX bytes:0 (0.0 b) > >[root@localhost root]# > >i see tunl0 and i dont know who made it and why is it there its always 0.0 b=20 >and its always there even if ppp0 isnt up , so i'd like to investigate this=20 >, is my machine compromised or a software made it , please help me with it . > >i though of running iptables to listen to what passes there . >any ideas ? >thanks in advance > > >_________________________________________________________________ >Surf the Web without missing calls! Get MSN Broadband.=20 >http://resourcecenter.msn.com/access/plans/freeactivation.asp Gilles L=C3=A9vesque, RHCE M.A.G. Datacom 373, rue T=C3=A9miscouata Rivi=C3=A8re-du-Loup (Qu=C3=A9bec) G5R 2Y9 T=C3=A9l=C3=A9phone : (418) 867-8656 T=C3=A9l=C3=A9copieur : (418) 867-3870 --=-mlJj2IWsjOrmX+VVaPAW Content-Type: text/html; charset=utf-8 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 TRANSITIONAL//EN"> <HTML> <HEAD> <META HTTP-EQUIV="Content-Type" CONTENT="text/html; CHARSET=UTF-8"> <META NAME="GENERATOR" CONTENT="GtkHTML/1.0.4"> </HEAD> <BODY> This is the TUN/TAP device take a look into your kernel configurations into Networkiing options <BR> (IP: tunneling). <BR> you can check out : <A HREF="http://anchor.cs.binghamton.edu/~mobileip/LJ/index.html">http://anchor.cs.binghamton.edu/~mobileip/LJ/index.html</A> <BR> <BR> <BR> <BR> >hello <BR> >i'm running a redhat machine and while checking <BR> >[root@localhost root]# ifconfig -a <BR> >lo Link encap:Local Loopback <BR> > LOOPBACK MTU:16436 Metric:1 <BR> > RX packets:316 errors:0 dropped:0 overruns:0 frame:0 <BR> > TX packets:316 errors:0 dropped:0 overruns:0 carrier:0 <BR> > collisions:0 txqueuelen:0 <BR> > RX bytes:15800 (15.4 Kb) TX bytes:15800 (15.4 Kb) <BR> > <BR> >ppp0 Link encap:Point-to-Point Protocol <BR> > inet addr:62.135.14.214 P-t-P:172.17.9.205 Mask:255.255.255.255 <BR> > UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1524 Metric:1 <BR> > RX packets:1739 errors:0 dropped:0 overruns:0 frame:0 <BR> > TX packets:1942 errors:0 dropped:0 overruns:0 carrier:0 <BR> > collisions:0 txqueuelen:3 <BR> > RX bytes:528941 (516.5 Kb) TX bytes:178970 (174.7 Kb) <BR> > <BR> >tunl0 Link encap:IPIP Tunnel HWaddr <BR> > NOARP MTU:1480 Metric:1 <BR> > RX packets:0 errors:0 dropped:0 overruns:0 frame:0 <BR> > TX packets:0 errors:0 dropped:0 overruns:0 carrier:0 <BR> > collisions:0 txqueuelen:0 <BR> > RX bytes:0 (0.0 b) TX bytes:0 (0.0 b) <BR> > <BR> >[root@localhost root]# <BR> > <BR> >i see tunl0 and i dont know who made it and why is it there its always 0.0 b <BR> >and its always there even if ppp0 isnt up , so i'd like to investigate this <BR> >, is my machine compromised or a software made it , please help me with it . <BR> > <BR> >i though of running iptables to listen to what passes there . <BR> >any ideas ? <BR> >thanks in advance <BR> > <BR> > <BR> >_________________________________________________________________ <BR> >Surf the Web without missing calls! Get MSN Broadband. <BR> ><A HREF="http://resourcecenter.msn.com/access/plans/freeactivation.asp">http://resourcecenter.msn.com/access/plans/freeactivation.asp</A> <BR> <BR> <TABLE CELLSPACING="0" CELLPADDING="0" WIDTH="100%"> <TR> <TD> <FONT SIZE="3"><B>Gilles Lévesque, RHCE</FONT></B> <BR> <FONT SIZE="3"><B>M.A.G. Datacom</FONT></B> <BR> 373, rue Témiscouata <BR> Rivière-du-Loup (Québec) <BR> G5R 2Y9 <BR> <FONT SIZE="2">Téléphone : (418) 867-8656</FONT> <BR> <FONT SIZE="2">Télécopieur : (418) 867-3870</FONT> <BR> </TD> </TR> </TABLE> </BODY> </HTML> --=-mlJj2IWsjOrmX+VVaPAW--