public inbox for gentoo-user@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-user] I've been hacked.
@ 2010-05-11  4:58 Grant
  2010-05-11  5:33 ` Mick
  0 siblings, 1 reply; 10+ messages in thread
From: Grant @ 2010-05-11  4:58 UTC (permalink / raw
  To: Gentoo mailing list

I nmap'ed one of my remote Gentoo servers today and besides the
expected open ports were these:

1080/tcp open  socks
3128/tcp open  squid-http
8080/tcp open  http-proxy

I'm not running any sort of proxy software that I know of and I should
be the only person whatsoever with access to the machine.  'netstat
-l' doesn't show any info on those ports at all so I suppose it's been
hacked as well?  I installed and ran 'rkhunter --check' (what happened
to the chrootkit ebuild?) but it doesn't seem to be much use since I
hadn't established a "file of stored file properties".

What do you guys think is going on?  What should I do from here?

- Grant



^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2010-05-12 12:06 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-05-11  4:58 [gentoo-user] I've been hacked Grant
2010-05-11  5:33 ` Mick
2010-05-11  6:54   ` Grant
2010-05-11  7:39     ` Norman Rieß
2010-05-11 14:09       ` Mick
2010-05-11 19:28         ` Grant
2010-05-11 19:40           ` Paul Hartman
2010-05-11 19:48           ` [gentoo-user] " Nikos Chantziaras
2010-05-12 11:40           ` [gentoo-user] " Adam
2010-05-11 14:29     ` Paul Hartman

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox