Re: Service: ingreslock (tcp/1524) (,none,eth0) - 3 packets

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Kevin Passey wrote:

Hi all,

I found this in my LogWatch so I started Googling and became very nervous that I had been hacked.

I checked for all the various /tmp/bob files etc - installed chkrootkit and ran it - nothing !! I've blocked all the relevant outgoing traffic on my router/firewall and installed firestarter.



I would run chkrootkit from a live CD. Specifically, I'd download and burn a LiveCD of knoppix-std or one of the others that has chrootkit, then I'd reboot with that CD, mount your old filesystem, and run chkrootkit that way. It's the only way to ensure that you don't have hostile kernel modules hiding themselves. Of course, if you have been rooted, I wouldn't expect that those log entries would have shown up...

Ben

--
redhat-list mailing list
unsubscribe mailto:redhat-list-request@xxxxxxxxxx?subject=unsubscribe
https://www.redhat.com/mailman/listinfo/redhat-list

[Index of Archives]     [CentOS]     [Kernel Development]     [PAM]     [Fedora Users]     [Red Hat Development]     [Big List of Linux Books]     [Linux Admin]     [Gimp]     [Asterisk PBX]     [Yosemite News]     [Red Hat Crash Utility]


  Powered by Linux