Security Basics mailing list archives

Re: Hacked ???


From: pg_vlad () hotmail com
Date: 1 Aug 2005 15:27:47 -0000

If you haven't configured that port for specific use, I would suggest denying all access to that port from all pc's 
inside and outside your network. Watch the logs, watch your apps see which (if any) complain about not bieng able to 
connect. If you don't use ICQ then someone may be using you. From the log it looks as if someone is looking into 
websites to possibly root them, unless the URL's posted are your traffic.

You can always nmap your box to see if it can give you clues as to what is running.

Also if you suspect a compromise, you should created a mirror log, and hopefully if your logs are deleted the attacker 
misses the mirrored log.


Current thread: