sigh.

Apr. 5th, 2005 09:05 am
rmd: (Default)
[personal profile] rmd
my home machine got rootkitted over the weekend. must rebuild tonite.

Date: 2005-04-05 09:41 pm (UTC)
From: [identity profile] rmd.livejournal.com
for redhat, "rpm -Va" checks all rpm-installed files and verifies them. look for the "5" in the status field on things like ls, ps, and netstat. that's a big danger sign.

blatant things that happened to me were my password getting changed on remote machines and local syslog files being blown away. also, tcpdump or snoop showing unusual network activity, or nmap (ideally from another machine) finding unusual ports open.

Profile

rmd: (Default)
rmd

June 2025

S M T W T F S
1234567
89 1011121314
15161718192021
22232425262728
2930     

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Jan. 22nd, 2026 08:33 pm
Powered by Dreamwidth Studios