sigh.

Apr. 5th, 2005 09:05 am
rmd: (Default)
[personal profile] rmd
my home machine got rootkitted over the weekend. must rebuild tonite.

Date: 2005-04-05 02:02 pm (UTC)
ceo: (Default)
From: [personal profile] ceo
Oh, suck. :-(

On that subject, can you recommend a tool for detecting whether one has been rootkitted? I think I should keep a closer eye on my machine than I do.

Date: 2005-04-05 02:19 pm (UTC)
coraline: (Default)
From: [personal profile] coraline
me too :/

Date: 2005-04-05 05:24 pm (UTC)
From: [identity profile] deguspice.livejournal.com
I'm not a Linux person, but I've heard people talk about using Tripwire to detect changed files. I think it does a checksum of important files and then periodically it recomputes the checksums and looks to see if anything has changed.

Date: 2005-04-05 08:40 pm (UTC)
From: [identity profile] frotz.livejournal.com
this (http://www.chkrootkit.org/) can be handy for the garden-variety varieties.

Date: 2005-04-05 09:41 pm (UTC)
From: [identity profile] rmd.livejournal.com
for redhat, "rpm -Va" checks all rpm-installed files and verifies them. look for the "5" in the status field on things like ls, ps, and netstat. that's a big danger sign.

blatant things that happened to me were my password getting changed on remote machines and local syslog files being blown away. also, tcpdump or snoop showing unusual network activity, or nmap (ideally from another machine) finding unusual ports open.

Profile

rmd: (Default)
rmd

June 2025

S M T W T F S
1234567
89 1011121314
15161718192021
22232425262728
2930     

Most Popular Tags

Page Summary

Style Credit

Expand Cut Tags

No cut tags
Page generated Jan. 22nd, 2026 07:55 pm
Powered by Dreamwidth Studios